Law Viewer

Back Home

REGULATIONS ON CYBERSECURITY SERVICES

Presidential Decree No. 34287, Mar. 5, 2024

 Article 1 (Purpose)
The purpose of this Decree is to prescribe matters necessary for the performance of cybersecurity services among the duties of the National Intelligence Service under Article 4 (1) of the National Intelligence Service Korea Act.
[This Article Wholly Amended on Mar. 5, 2024]
 Article 2 (Definitions)
The terms used in this Decree are defined as follows: <Amended on Mar. 5, 2024>
1. The term "information and communications network" means an information and communications system through which information is collected, processed, stored, searched, transmitted, or received by using telecommunications systems under subparagraph 2 of Article 2 of the Telecommunications Business Act or by utilizing telecommunications systems, computers, and computer technologies;
2. The term "cyber-attack and threat" means the act of intrusion, disturbance, paralysis, or destruction of information and communications devices, information and communications networks, or information-related information systems by electronic means, such as hacking, computer viruses, distributed denial of services (DDoS), electronic waves, or other electronic means, or forgery, alteration, damage, or steal of information, and threats related thereto.
 Article 3 (Performance of Cybersecurity Services)
The National Intelligence Service shall perform the following services for cybersecurity (hereinafter referred to as "cybersecurity services"):
1. Cybersecurity information services:
(a) Collecting, preparing, and distributing information related to cybersecurity, such as international and national hacker organizations, etc., pursuant to Article 4 (1) 1 (e) of the National Intelligence Service Korea Act (hereinafter referred to as the "Act");
(b) Countermeasures taken to verify, control, and block the activities of North Korea, foreign countries, foreigners, foreign organizations, transnational offenders, or Korean nationals who are against the national security and national interests, which are related to the collection, preparation, and distribution of information related to cybersecurity pursuant to Article 4 (1) 3 of the Act, and to protect the safety of the people;
(c) Planning and coordination of affairs referred to in items (a) and (b) performed pursuant to Article 4 (1) 5 of the Act;
2. Cybersecurity services:
(a) Prevention of and countermeasures to cyberattacks and threats targeting the organizations under Article 4 (1) 4 of the Act (hereinafter referred to as "central administrative agencies, etc.");
(b) Planning and coordination services related to the prevention of and countermeasures to cyberattacks and threats pursuant to Article 4 (1) 5 of the Act.
[This Article Wholly Amended on Mar. 5, 2024]
 Article 3-2 (Planning and Coordination of Cybersecurity Services)
(1) The Director of the National Intelligence Service shall perform planning affairs, such as the formulation of policies on cybersecurity information affairs under subparagraph 1 of Article 3 (hereinafter referred to as "cybersecurity information services") and cybersecurity affairs under subparagraph 2 of that Article (hereinafter referred to as "cybersecurity services"), and shall formulate and implement the following guidelines, etc. in order to efficiently and systematically perform cybersecurity information services and cybersecurity services:
1. Basic guidelines for cybersecurity information services;
2. Basic guidelines for cybersecurity services;
3. Occasional security measures to respond to new types of cyber attacks threats.
(2) Where it is necessary to coordinate cybersecurity information affairs and cybersecurity affairs, the Director of the National Intelligence Service shall directly coordinate emergency issues that have a significant impact on national security, and other issues shall be coordinated as prescribed by the basic guidelines under paragraph (1) 1 and 2.
[This Article Added on Mar. 5, 2024]
 Article 4 (National Cybersecurity Center)
(1) The Director of the National Intelligence Service may establish the National Cyber Security Center to efficiently conduct cyber security services.
(2) The National Cyber Security Center under paragraph (1) may have an organization dedicated to establish and operate a public-private joint response system under Article 6-2 (4). <Added on Mar. 5, 2024>
(3) The National Cyber Security Center under paragraph (1) may establish and operate an advisory group comprised of relevant experts in order to professionally examine matters concerning cyber security in the National Cyber Security Center under paragraph (1). <Added on Mar. 5, 2024>
(4) Where necessary for the operation of the National Cyber Security Center under paragraph (1), the Director of the National Intelligence Service may request the heads of State agencies or other related agencies or organizations under Article 5 (1) of the Act (hereinafter referred to as "State agencies, etc.") to provide cooperation, such as dispatching public officials, executive officers, employees, etc. under their jurisdiction. <Amended on Mar. 5, 2024>
 Article 5 (Establishment of Inter-Agency Cooperation System)
The Director of the National Intelligence Service may establish an information cooperation system with state agencies, etc., foreign intelligence and security agencies, or other related agencies, if necessary for conducting cyber security information services.
[This Article Wholly Amended on Mar. 5, 2024]
 Article 5-2 (Voluntary Submission of Cyber Security Information)
Where the Director of the National Intelligence Service conducts an investigation necessary to collect information related to cyber security pursuant to Article 5 (2) of the Act, the owner, holder, or keeper of digital data, etc. contained and recorded with information related to cybersecurity may arbitrarily submit such digital data, etc. to the Director of the National Intelligence Service in response to such investigation: Provided, That where such digital data, etc. constitute communication confirmation data under subparagraph 11 of Article 2 of the Protection of Communications Secrets Act, consent from the parties under subparagraph 4 of Article 2 of that Act shall be obtained.
[This Article Added on Mar. 5, 2024]
 Article 5-3 (Preparation of Cyber Security Information)
The Director of the National Intelligence Service shall compile, analyze, and evaluate domestic and foreign information collected through cyber security information services and prepare cyber security information, including the level of hazards, the impact on national security, and countermeasures to protect the safety of the people, by integrating, analyzing, and evaluating domestic and foreign information collected through cyber security information services.
[This Article Added on Mar. 5, 2024]
 Article 6 (Establishment of Information Sharing System)
(1) The Director of the National Intelligence Service may establish and operate an information sharing system to distribute and share information related to cyber security. <Amended on Mar. 5, 2024>
(2) The Director of the National Intelligence Service shall determine matters necessary for the operation of the information sharing system under paragraph (1), such as the objects and scope of utilization of the information sharing system, in consultation with the relevant central administrative agencies, etc.
 Article 6-2 (Response Measures Related to Performance of Duties of Cyber Security Information)
(1) The Director of the National Intelligence Service may conduct technical tests and analysis of information and communications devices and software in order to verify the safety of information and communications devices and software, which are abused or potentially likely to be abused for activities contrary to national security and national interests, in order to verify the safety of information and communications devices and software.
(2) The Director of the National Intelligence Service may request State agencies, etc. to take necessary measures to minimize risks based on the results of testing and analysis under paragraph (1), and State agencies, etc. in receipt of such request may request the Director of the National Intelligence Service to provide support for the implementation of necessary measures.
(3) The Director of the National Intelligence Service may take necessary measures, such as tracking, neutralizing, etc., overseas and overseas bases located in North Korea, in order to preemptively identify, control, check, and block activities, such as international and national hacking organizations, which are contrary to national security and national interests.
(4) The Director of the National Intelligence Service may establish and operate a public-private joint integrated response system to manage crisis situations in consultation with the Minister of National Security, as countermeasures to protect the safety of the people from activities contrary to national security or national interests.
[This Article Added on Mar. 5, 2024]
 Article 7 (Scope of Public Institutions Subject to Cyber Security Services)
Public Institutions prescribed by Presidential Decree in Article 4 (1) 4 (c) of the Act means the following institutions: <Amended on Mar. 5, 2024>
2. Local government-invested public corporations and local government public corporations established under the Local Public Enterprises Act;
2-2. Institutions prescribed by Municipal Ordinance of the relevant local government, among institutions provided with local government-invested or -funded institutions under Article 2 (1) of the Act on the Operation of Local Government-Invested or -Funded Institutions;
3. Corporations established under Special Acts: Provided, That local cultural centers under the Promotion of Promotion of Local Cultural Centers Act and associations established under the Special Acts shall be excluded herefrom;
4. National or public Schools established under the Elementary and Secondary Education Act, the Higher Education Act, and other Acts;
[Title Amended on Mar. 5, 2024]
 Article 8 (Formulation and Implementation of Detailed Guidelines for Cyber Security)
The heads of central administrative agencies, etc. shall formulate and implement detailed guidelines for cyber security for the relevant agencies in accordance with the basic guidelines under Article 3-2 (1) 2, reflecting the characteristics, level of security, etc. of the relevant agencies.
[This Article Wholly Amended on Mar. 5, 2024]
 Article 9 (Preventive Measures against Cyber Security)
(1) The Director of the National Intelligence Service may conduct a security review of informatization projects implemented by the heads of central administrative agencies, etc. (including projects in accordance with intelligent informatization plans under Article 11 (1) of the Framework Act on Intelligent Informatization) in order to prevent cyber attacks and threats against central administrative agencies, etc., and may verify whether the results of such security review are fulfilled.
(2) The Director of the National Intelligence Service may formulate security measures for the introduction and operation of information protection systems, encryption devices, encryption module, and information and communications devices with security functions (hereinafter referred to as "information protection systems, etc.") of central administrative agencies, etc. and for the use of cloud computing services defined in subparagraph 3 of Article 2 of the Act on the Development of Cloud Computing and Protection of Its Users (hereafter referred to as "cloud computing services" in this Article) <Amended on Mar. 5, 2024>
(3) The Director of the National Intelligence Service may verify whether the information protection systems, etc. and cloud computing services introduced, operated or used by central administrative agencies, etc. meet the security measures under paragraph (2). <Amended on Mar. 5, 2024>
(4) The Director of the National Intelligence Service may directly develop information security systems, etc. and disseminate them to central administrative agencies, etc.
(5) The Director of the National Intelligence Service may measure the level of security management to identify and improve vulnerabilities of information and communications apparatus, information and communications networks or information systems related to information and communications, etc. of central administrative agencies, etc. In such cases, he or she shall notify the heads of the relevant central administrative agencies, etc. of the items, procedures, timing, etc. thereof in advance. <Amended on Mar. 5, 2024>
(6) Notwithstanding paragraph (5), the Minister of National Defense shall measure the level of security management of the agencies determined by consultation between the Director of the National Intelligence Service and the Minister of National Defense from among the agencies referred to in the subparagraphs of Article 7, which are determined by the Minister of National Defense. If the Minister of National Defense deems it necessary for national security or at the request of the Director of the National Intelligence Service, the Minister of National Defense shall notify the Director of the National Intelligence Service of the relevant details. <Added on Mar. 5, 2024>
[Title Amended on Mar. 5, 2024]
 Article 10 (Cyber Security Education)
(1) The head of each central administrative agency, etc. shall provide education necessary to enhance the awareness of cyber security of public officials, executive officers, and employees under his or her jurisdiction on cyber security and the job ability of public officials, executive officers, and employees under his or her jurisdiction performing cyber security services. <Amended on Mar. 5, 2024>
(2) Where necessary for cyber security education under paragraph (1), the Director of the National Intelligence Service may directly operate related curricula or designate curricula operated by other institutions or organizations as cyber security education. <Amended on Mar. 5, 2024>
(3) The head of a central administrative agency, etc. may request the Director of the National Intelligence Service to provide support necessary for cyber security education under paragraph (1). <Added on Mar. 5, 2024>
[Title Amended on Mar. 5, 2024]
 Article 11 (Cyber Security Training)
(1) The heads of central administrative agencies, etc. shall conduct training every year to respond to cyber attacks and threats against the relevant agencies.
(2) The Director of the National Intelligence Service may conduct integrated training in preparation for cyber attacks and threats against central administrative agencies, etc. in consultation with the Director of the Office of National Security.
(3) Where the Director of the National Intelligence Service intends to conduct an integrated training under paragraph (2), he or she shall notify the head of the relevant central administrative agency, etc. of the training schedule, etc. in advance, unless there is a compelling reason not to do so.
(4) Where the Director of the National Intelligence Service deems it necessary as a result of the integrated training under paragraph (2), he or she may request the head of the relevant central administrative agency, etc. to take corrective measures.
(5) Necessary matters concerning the scope and details of the training under paragraph (1) and the integrated training under paragraph (2) shall be determined by the Director of the National Intelligence Service.
[Title Amended on Mar. 5, 2024]
 Article 12 (Self-Diagnosis and Checkup of Cyber Security)
(1) The head of a central administrative agency, etc. shall conduct self-diagnosis and checkup necessary for the prevention of and response to cyber attacks and threats against the relevant agency at least once a year. <Amended on Mar. 5, 2024>
(2) Notwithstanding paragraph (1), where the head of a central administrative agency, etc. takes any of the following measures, he or she shall be deemed to have conducted self-diagnosis and checkup under paragraph (1): <Amended on Mar. 5, 2024>
1. Deleted; <Mar. 5, 2024>
2. Analysis and evaluation of vulnerabilities under article 9 of the Act on the Protection of Information and Communications Infrastructure;
3. Measurement of levels of security management under Article 9 (5);
4. Analysis and evaluation of vulnerability of electronic financial infrastructure under article 21-3 of the Electronic Financial Transactions Act.
(3) Where the head of a central administrative agency, etc. discovers vulnerable elements as a result of the diagnosis and checkup under paragraph (1), he or she shall take necessary measures, such as correction thereof.
(4) The Director of the National Intelligence Service may request the heads of central administrative agencies, etc. whose cyber attacks or threats have occurred or are likely to occur to submit the results of self-examination and inspection under paragraph (1) and the results of measures taken under paragraph (3). Upon receipt of such request, the heads of central administrative agencies, etc. shall comply therewith, unless there is a compelling reason not to do so. <Added on Mar. 5, 2024>
[Title Amended on Mar. 5, 2024]
 Article 13 (Assessment of Actual Status of Cyber Security)
(1) The Director of the National Intelligence Service may conduct an assessment on the actual status of cyber security, such as the organization, human resources, budget, education on duties, and self-diagnosis and checkup of cyber security for central administrative agencies, etc. to perform cyber security services. <Amended on Mar. 5, 2024>
(2) Where the Director of the National Intelligence Service intends to conduct an assessment under paragraph (1), he or she shall notify the head of the relevant central administrative agency, etc. of the items, procedures, timing, etc. of the assessment in advance.
(3) The Director of the National Intelligence Service shall notify the head of the relevant central administrative agency, etc. of the results of an assessment under paragraph (1).
(4) Where the head of the relevant central administrative agency, etc. who has been notified of the results of an assessment pursuant to paragraph (3) finds any problem as a result of such assessment, he or she shall prepare improvement measures and notify the Director of the National Intelligence Service of such measures within 3 months from the date he or she is notified of the results of such assessment. <Added on Mar. 5, 2024>
(5) The Director of the National Intelligence Service may verify whether the improvement measures notified by the head of a central administrative agency, etc. pursuant to paragraph (4) have been implemented. <Added on Mar. 5, 2024>
(6) The Director of the National Intelligence Service may disclose the results of the assessment on the actual status under paragraph (1) to the extent that it does not interfere with national security. <Added on Mar. 5, 2024>
(7) The Director of the National Intelligence Service may utilize relevant experts if necessary for efficiently conducting evaluation under paragraph (1) and professional and technical research, etc. on evaluation. <Added on Mar. 5, 2024>
[Title Amended on Mar. 5, 2024]
 Article 14 (Integrated Security Control)
(1) The Director of the National Intelligence Service shall establish and operate an integrated security control system to immediately detect and respond to cyber attacks and threats against central administrative agencies, etc. (hereinafter referred to as "security control"). <Amended on Mar. 5, 2024>
(2) The head of a central administrative agency, etc. shall establish and operate a security control center linked to the integrated security control system referred to in paragraph (1) for the security control of the relevant agency: Provided, That where it is more efficient to utilize the security control center operated by another agency, the head of a central administrative agency, etc. may utilize the security control center of another agency without directly establishing it. <Amended on Mar. 5, 2024>
(3) The Director of the National Intelligence Service may conduct security control of the relevant central administrative agencies, etc. jointly with the heads of central administrative agencies, etc. by utilizing the integrated security control system under paragraph (1). <Amended on Mar. 5, 2024>
(4) The Director of the National Intelligence Service may request necessary cooperation or support from cloud computing service providers under subparagraph 4 of Article 2 of the Act on the Development of Cloud Computing and Protection of Its Users pursuant to Article 5 (1) of the Act for security control under paragraph (3). <Added on Mar. 5, 2024>
(5) Except as provided in paragraphs (1) through (4), the establishment and operation of a security control center and other necessary matters shall be determined by the Director of the National Intelligence Service in consultation with the heads of the relevant central administrative agencies. <Amended on Mar. 5, 2024>
[Title Amended on Mar. 5, 2024]
 Article 15 (Issuance of Warning)
(1) The Director of the National Intelligence Service may issue an alert on a step-by-step basis to systematically respond to and prepare for cyber attacks and threats against central administrative agencies, etc. in consideration of the ripple impact, the scale of damage, etc. In such cases, he or she shall consult with the Director of the Office of National Security in advance.
(2) Notwithstanding paragraph (1), the Minister of National Defense shall issue a warning to the agencies determined by consultation between the Director of the National Intelligence Service and the Minister of National Defense, among the agencies referred to in the subparagraphs of Article 7. In such cases, if deemed necessary for national security or at the request of the Director of the National Intelligence Service, the Minister of National Defense shall notify the Director of the National Intelligence Service of the relevant details. <Amended on Mar. 5, 2024>
(3) The Director of the National Intelligence Service, the Minister of National Defense, and the head of a central administrative agency who issues a warning to respond to and prepare for cyber attacks and threats pursuant to other statutes and regulations shall exchange information related to a warning before issuing a warning in order to efficiently perform affairs related to a warning at the national level. <Amended on Mar. 5, 2024>
 Article 16 (Investigation of Accidents)
(1) Where an accident occurs due to a cyber attack or threat against central administrative agencies, etc., the Director of the National Intelligence Service may conduct an investigation to identify the subject of the attack, analyze the cause thereof, and identify the details of damage, etc.: Provided, That the Minister of National Defense may conduct an investigation into the agencies determined through consultation with the Director of the National Intelligence Service and the Minister of National Defense among the agencies referred to in the subparagraphs of Article 7. <Amended on Mar. 5, 2024>
(2) Notwithstanding paragraph (1), where the Director of the National Intelligence Service or the Minister of National Defense deems that an accident caused by cyber attacks or threats against central administrative agencies, etc. does not constitute any harmful act, such as international and national hacking organizations, etc. or other minor accidents, he or she may require the head of the relevant central administrative agencies, etc. to conduct an investigation by himself or herself. <Amended on Mar. 5, 2024>
(3) The Director of the National Intelligence Service may jointly evaluate the impact on national security, national interests, and Government policies on data deemed divulged by the relevant accident as a result of an investigation conducted under paragraphs (1) and (2) with the head of the relevant central administrative agency, etc.
(4) The Director of the National Intelligence Service may request the head of the relevant central administrative agency, etc. to take measures necessary to minimize impacts on national security, national interests, and Government policies under paragraph (3).
(5) The Director of the National Intelligence Service may request the head of a central administrative agency, etc. to submit a report on the results of an investigation under the proviso of paragraph (1) and paragraph (2) and the results of measures taken under paragraph (4), if necessary in connection with the performance of cyber security services. Upon receipt of such request in such cases, the head of the central administrative agency, etc. shall comply therewith, unless there is a compelling reason not to do so. <Added on Mar. 5, 2024>
 Article 17 (Research and Development of Strategies Related to Cyber Security Services)
(1) The Director of the National Intelligence Service may research and develop strategies, policies, and technologies necessary for conducting cyber security services.
(2) The Director of the National Intelligence Service may designate any of the following institutions as a specialized institution for research and development under paragraph (1): <Amended on Mar. 5, 2024>
2. A non-profit corporation established pursuant to Article 32 of the Civil Act, which is an academic society or academic organization related to cyber security.
(3) Detailed matters necessary for designating a specialized institution under paragraph (2), such as the standards and procedures for designation, methods of designation, etc., shall be determined by the Director of the National Intelligence Service. <Added on Mar. 5, 2024>
(4) The Director of the National Intelligence Service may fully or partially subsidize expenses incurred in performing the duties of a specialized institution designated pursuant to paragraph (2) within budgetary limits. <Amended on Mar. 5, 2024>
 Article 18 (Management of Personally Identifiable Information)
The Director of the National Intelligence Service and the head of a central administrative agency, etc. may manage data containing resident registration numbers or alien registration numbers under subparagraph 1 or 4 of Article 19 of the Enforcement Decree of the Personal Information Protection Act, if it is inevitable to perform the following duties: <Amended on Mar. 5, 2024>
1. Research for cyber security information services under Article 5 (2) of the Act;
2. Investigations of accidents under Article 16.
ADDENDA <Presidential Decree No. 31356, Dec. 31, 2020>
Article 1 (Enforcement Date)
This Decree shall enter into force on Jan. 1, 2021.
Article 2 (Transitional Measures concerning Basic Measures for Cyber Security)
(1) A basic plan for national cyber security formulated and implemented by the Director of the National Intelligence Service as at the time this Decree enters into force shall be deemed a basic measure for cyber security under Article 8 (1).
(2) Cyber security measures formulated and implemented by the heads of central administrative agencies, etc. as at the time this Decree enters into force shall be deemed detailed cyber security measures under Article 8 (2).
Article 3 (Transitional Measures concerning Security Control Center)
A security control center established and operated by the head of a central administrative agency, etc. as at the time this Decree enters into force shall be deemed a security control center under Article 14 (2).
Article 4 (Transitional Measures concerning Issuance of Warning)
Where a warning has not yet been lifted because a warning has been issued before this Decree enters into force, it shall be deemed that a warning has been issued pursuant to Article 15.
ADDENDA <Presidential Decree No. 34287, Mar. 5, 2024>
Article 1 (Enforcement Date)
This Decree shall enter into force on the date of its promulgation: Provided, That the amended provision of Article 10 shall enter into force on January 1, 2025.
Article 2 (Applicability to Preparation of Improvement Measures Based on Findings from Assessment on Actual Status of Cyber Security)
The amended provisions of Article 13 (4) and (5) shall begin to apply where the Director of the National Intelligence Service conducts an assessment on the actual status of cyber security pursuant to the amended provisions of Article 13 (1) after this Decree enters into force.