CHAPTER I GENERAL PROVISIONS
The terms used in this Decree are defined as follows: <Amended on Jan. 14, 2020; Jul. 14, 2020; Dec. 31, 2020>
| 3. | The term "central administrative agency, etc." means the Ministries and agencies (including committees equivalent thereto) under Article 2 (2) of the Government Organization Act, subordinate, assistant, and security agencies under the jurisdiction of the President, assistant agencies of the Prime Minister, and the Corruption Investigation Office for High-Ranking Officials; |
| 4. | The term "cryptographic material" means a device or means to which cryptographic technology is applied for the protection of classified information and the security of information and communications, and which is classified into the cryptographic materials used for communicating Top Secret, Secret, and Confidential information. |
| Article 3 (Security responsibility) |
A person who manages any of the following matters and the head of a relevant agency (referring to agencies of various levels and managing agencies under Article 33 (3); hereinafter the same shall apply) shall bear the security responsibility for the relevant matters subject to management: | 1. | Documents, materials, facilities, and areas that fall under State secrets; |
| 2. | Personnel dealing with State secrets limited to national security. |
[This Article Wholly Amended on Dec. 31, 2020]
| Article 3-2 (Formulation of framework security policies) |
The Director of the National Intelligence Service shall perform the following business affairs in relation to security services: <Amended on Jan. 14, 2020; Dec. 31, 2020>
| 1. | Establishment of framework policies and improvement of systems related to security services; |
| 2. | Research, dissemination, and standardization of techniques for performing security services; |
| 3. | Development and dissemination of technology related to security services by electronic means; |
| 4. | Verification of whether agencies of various levels perform the security services properly in accordance with the matters referred to in subparagraphs 1 through 3, and the analysis and evaluation of the results thereof; |
| 5. | The following business affairs for the prevention, etc. of an incident falling under any subparagraph of Article 38 (hereinafter referred to as "security incident"): |
| (b) | Background investigation under Article 36 (1); |
| (c) | Security incident investigations under Article 38; |
| (d) | Other support for security services of agencies of various levels, such as detecting against wiretapping, security education, and consulting; |
| 6. | Deleted. <Dec. 31, 2020> |
[Title Amended on Jan. 14, 2020]
[Moved from Article 6 <Jan. 14, 2020>]
| Article 3-3 (Security examination committee) |
| (1) | A security examination committee shall be established in a central administrative agency, etc. to deliberate on important matters regarding the performance of security services of the relevant agency, such as disclosure of classified information. <Amended on Jan. 14, 2020; Dec. 31, 2020> |
| (2) | The Director of the National Intelligence Service shall determine the details necessary for the composition and operation of a security examination committee under paragraph (1). |
[Moved from Article 26 <Jan. 14, 2020>]
CHAPTER II PROTECTION OF CLASSIFIED INFORMATION
| Article 4 (Categories of classified information) |
Classified information shall be categorized based on its significance and degree of value, in the following manner:
| 1. | Top Secret: Classified information that, if divulged, would likely to result in the severance of diplomatic relations with the Republic of Korea and the outbreak of war, and jeopardize the national defense planning and information activities and the development of science and technology essential for national defense, etc.; |
| 2. | Secret: Classified information that, if divulged, would likely to seriously impede national security; |
| 3. | Confidential: Classified information that, if divulged, would likely to harm national security. |
| Article 5 (Principles of protection and management of classified information) |
The heads of agencies of various levels shall formulate and implement security measures to prevent classified information from being divulged or leaked in the entire process of preparation, classification, handling, distribution, transfer, etc. of classified information. In such cases, data containing information that can infer the content of the relevant classified information, such as the title of classified information, shall not be disclosed. <Amended on Jan. 14, 2020>
[(Previous) Article 6 moved to Article 3-2 <Jan. 14, 2020>]
| Article 7 (Manufacture, supply, and return of cryptographic materials) |
| (1) | The Director of the National Intelligence Service shall manufacture cryptographic materials and supply them to agencies in need of them; provided, if deemed necessary by the Director of the National Intelligence Service, an agency using cryptographic materials may manufacture such cryptographic materials within the scope of encryption systems authorized by the Director of the National Intelligence Service. <Amended on Jan. 14, 2020> |
| (2) | The head of an agency that uses cryptographic materials shall, without delay, return the cryptographic materials, the period of use of which has expired, to the head of the relevant manufacturing agency. |
| Article 8 (Handling of classified information and cryptographic materials) |
Classified information may be handled only by a person who has obtained a security clearance for handling classified information of the relevant level, and cryptographic materials may be handled only by a person who has obtained a security clearance for handling cryptographic materials used for communicating classified information of the relevant level. <Amended on Jan. 14, 2020>
[Title Amended on Jan. 14, 2020]
| Article 9 (Persons with authority to grant security clearances for handling classified information and cryptographic materials) |
| (1) | Persons with the authority to grant security clearances for handling Top Secret information and cryptographic materials used for communicating Top Secret and Secret information shall be as follows: <Amended on Jul. 26, 2017; Dec. 4, 2018; Jan. 14, 2020; Jul. 14, 2020; Aug. 4, 2020> |
| 3. | The Chairperson of the Board of Audit and Inspection; |
| 4. | The Chairperson of the National Human Rights Commission of Korea; |
| 4-2. | The Chief Prosecutor of the Corruption Investigation Office for High-Ranking Officials; |
| 5. | The head of respective Ministry; |
| 6. | The Minister of the Office for Government Policy Coordination, the Chairperson of the Korea Communications Commission, the Chairperson of the Fair Trade Commission, the Chairperson of the Anti-Corruption and Civil Rights Commission, the Chairperson of the Personal Information Protection Commission, and the Chairperson of the Nuclear Safety and Security Commission; |
| 7. | The Chief of Staff to the President; |
| 8. | The Director of the Office of National Security; |
| 9. | The Chief of the Presidential Security Service; |
| 10. | The Director of the National Intelligence Service; |
| 11. | The Prosecutor General; |
| 12. | The Chairperson of the Joint Chiefs of Staff, the Chiefs of Staff of the respective armed forces, the Commander of the Ground Operations Command, and the Commander of the Army 2nd Operations Command; |
| 13. | The commander of each military unit designated by the Minister of National Defense. |
| (2) | Persons with the authority to grant security clearances for handling Secret and Confidential information and cryptographic materials used for communicating Confidential information shall be as follows: <Amended on Dec. 31, 2020> |
| 1. | Persons referred to in the subparagraphs of paragraph (1); |
| 2. | The head of a Service, which is a central administrative agency, etc.; |
| 3. | The head of a local government; |
| 4. | The Superintendent of Education of the Special Metropolitan City, a Metropolitan City, a Do, a Special Self-Governing City, and a Special Self-Governing Province; |
| 5. | The head of an agency designated by a person referred to in subparagraphs 1 through 4. |
[Title Amended on Jan. 14, 2020]
| Article 10 (Grant and revocation of security clearances for handling classified information and cryptographic materials) |
| (1) | A person with the authority to grant security clearances for handling classified information shall grant security clearances for the classified information of the relevant level to a person who will handle or have access to the classified information, and change the clearance level, if necessary. |
| (2) | Security clearances shall be limited to the minimum number of personnel required based on the position of the person being cleared. |
| (3) | If a person who has obtained a security clearance falls under any of the following subparagraphs, the security clearance shall be revoked: <Amended on Jan. 14, 2020; Dec. 31, 2020> |
| 1. | Where he or she has committed a security incident or has interfered with security services by intent or gross negligence, in violation of this Decree; |
| 2. | Where confidentiality becomes unnecessary. |
| (4) | A person with the authority to grant security clearances for handling cryptographic materials shall grant a security clearance for handling cryptographic materials used for communicating classified information of the relevant level to a person who needs to handle cryptographic materials from among persons who have obtained a security clearance for handling classified information, and shall change the clearance level, if necessary. In such cases, the clearance level to handle cryptographic materials shall not be higher than the clearance level to handle classified information. <Added on Jan. 14, 2020> |
| (5) | If a person who has obtained a security clearance for handling cryptographic materials falls under any of the following subparagraphs, his or her security clearance shall be revoked: <Added on Jan. 14, 2020> |
| 1. | Where his or her security clearance is revoked; |
| 2. | Where he or she has committed a security incident in connection with cryptographic materials or has impeded security services by violating this Decree; |
| 3. | Where he or she no longer needs to handle cryptographic materials. |
| (6) | The grant of security clearances for handling classified information and cryptographic materials, the change of clearance levels, and the revocation of security clearances shall be made in writing, and such fact shall be included in the personnel records of employees. <Amended on Jan. 14, 2020> |
[Title Amended on Jan. 14, 2020]
| Article 11 (Classifications) |
| (1) | A person who has obtained a security clearance shall have the right to classify information of the security clearance level he or she has or lower. |
| (2) | Among persons who have obtained a security clearance of the same level or higher, a person in an immediate supervisory position may adjust the classification level of classified information assigned by a person in a position lower than him or her. |
| (3) | A person who originates or manages classified information shall be responsible for classifying or reclassifying information as soon as he or she completes the preparation of classified information or receives classified information. <Amended on Jan. 14, 2020> |
| Article 12 (Classification principles) |
| (1) | Classified information shall be assigned the lowest classification level that can ensure its adequate protection, avoiding both over-classification and under-classification. |
| (2) | Classified information shall be categorized according to their content and value, and not in relation to other classified information. |
| (3) | Classified information received from a foreign government or international organization shall be classified to provide the degree of protection required by the originating agency. |
| Article 13 (Classification guidelines) |
The heads of agencies of various levels shall prepare and implement detailed classification guidelines in order to ensure uniformity and appropriateness in categorizing classified information. In such cases, detailed classification guidelines shall not be disclosed. <Amended on Jan. 14, 2020>
| Article 14 (Advance notice) |
| Article 15 (Reclassification) |
| (1) | In order to protect classified information efficiently, reclassification shall be made, such as changing the classification level or the advance notice. |
| (2) | Reclassification shall be made in accordance with the markings of the classified information or ex officio by the originator; provided, in any of the following cases, classified information may be destroyed regardless of the protection period and the preservation period of the classified information stated in the advance notice: |
| 1. | Where emergencies or unavoidable circumstances, such as war or natural disaster, prevent the continued custody or safe removal of classified information; |
| 2. | Where requested by Director of National Intelligence Service; |
| 3. | Where it is no longer necessary to retain the classified information until the time of destruction stated in the advance notice due to the reclassification of classified information and prior approval is obtained from the person with the authority to grant security clearances for handling the relevant classified information. |
| (3) | if there is no marking included in the classified information received from a foreign government or international organization, or if it is deemed that the marking is inappropriate to manage classified information, the head of the receiving agency may reclassify the classified information to the extent that the classified information can be protected as much as possible. |
In order to warn the handler or manager and to prevent access by persons not authorized to handle classified information, classified information shall be marked to indicate its classification level as soon as the classification (including reclassification; hereinafter the same shall apply) is made.
| Article 17 (Receipt and transmission of classified information) |
| (1) | When receiving or transmitting classified information, a method that can protect the information to the maximum extent shall be used. |
| (2) | No classified information shall be received or transmitted using any information and communications means without being encrypted. <Amended on Jan. 14, 2020> |
| (3) | When receiving or transmitting any classified information, a receipt shall be used to confirm the fact. |
Classified information shall be stored in appropriate facilities that can protect it from theft, leakage, fire, or destruction and prevent access by persons not authorized to handle classified information.
| Article 19 (Storage of classified information during business trip) |
A person on a business trip carrying classified information may entrust the custody of such classified information to a domestic police agency or a diplomatic mission abroad in order to safely protect such classified information, and the entrusted agency shall keep such classified information in its custody.
The heads of agencies of various levels shall appoint custodians to perform the duties of custody of classified information under this Decree from among their employees.
| Article 21 (Electronic management of classified information) |
| (1) | The heads of agencies of various levels may manage classified information by using electronic means, and may establish and operate an electronic classified information management system. <Amended on Jan. 14, 2020> |
| (2) | When the heads of agencies of various levels manage classified information under paragraph (1), they shall prepare and implement security measures to prevent the forgery, alteration, damage, leakage, etc. of classified information, using cryptographic materials the safety of which has been verified by the Director of the National Intelligence Service. |
| (3) | The Director of the National Intelligence Service may establish and operate an integrated classified information management system for shared use by agencies of various levels with limited classified information holdings. <Added on Jan. 14, 2020> |
| Article 22 (Classified information management record) |
| (1) | The heads of agencies of various levels shall prepare and keep a classified information management record to register all management details necessary for the preparation, categorization, receipt, transmission, handling, etc. of classified information; provided, the Top Secret management record shall be separately prepared and kept, and cryptographic materials shall be managed in the cryptographic materials management record. |
| (2) | The classified information management record and the cryptographic materials management record shall accurately register and maintain security responsibilities and security management details for all classified information and cryptographic materials. |
| Article 23 (Restrictions on reproduction and copying of classified information) |
| (1) | No act of reproducing the original form, such as copying, typing, printing, engraving, recording, photographing, printing, enlarging, etc., may be performed with respect to part or all of classified information or cryptographic materials; provided, the same shall not apply to classified information categorized as follows: |
| 1. | Top Secret: Where permission is obtained from the originator; |
| 2. | Secret and Confidential: Where the originator has not imposed any specific restrictions and it is a classified information for shared use among persons who have obtained authorization for handling the relevant level of classified information; |
| 3. | Classified information managed by electronic means: Where such classified information is for the purpose of storing the relevant classified information. |
| (2) | The heads of agencies of various levels may, if deemed necessary for the efficient performance of security services, make and store copies of classified information under the proviso of paragraph (1) within the retention period of the relevant classified information, if deemed necessary. |
| (4) | If classified information is reproduced or duplicated, the same classification level and advance notice as the original shall be entered, and a copy number shall be assigned. |
| (5) | When classified information is marked for “destruction” upon reclassification under paragraph (4), it may be destroyed earlier than the protection period of the original. <Amended on Jan. 14, 2020> |
| Article 24 (Perusal of classified information) |
| (1) | Only a person whose duties are directly related to the classified information from among those who have obtained a security clearance for handling classified information of the relevant level may inspect the classified information. |
| (2) | When a person not authorized to handle classified information is allowed to peruse or handle classified information, the head of the agency to which he or she belongs (referring to the Minister of National Defense if the classified information is related to military affairs) shall confirm in advance the personal information of the person who intends to peruse the classified information, the details of the classified information to be perused, etc., and take security measures, such as preparing self-security measures necessary for protecting classified information at the time of perusal, as determined by the Director of the National Intelligence Service; provided, with respect to the security measures for Top Secret information, he or she shall have a prior consultation with the Director of the National Intelligence Service. |
| Article 25 (Disclosure of classified information) |
| (1) | In any of the following cases, the head of a central administrative agency, etc. may disclose classified information originated by him or her after deliberation by the security examination committee under Article 3-3; provided, he or she shall have a prior consultation with the Director of the National Intelligence Service in the case of the disclosure of Top Secret information: <Amended on Jan. 14, 2020; Dec. 31, 2020> |
| 1. | Where it is deemed necessary to urgently notify the public in order to ensure national security; |
| 2. | Where disclosure is deemed significantly beneficial to national security or interests. |
| (2) | Except as provided in statutes, no public official or former public official shall disclose classified information without approval from the head of the agency to which he or she belongs or belonged. |
[(previous) Article 26 moved to Article 3-3 <Jan. 14, 2020>]
| Article 27 (Removal of classified information) |
Classified information shall not be removed from the facility where it is kept; provided, when it is necessary to remove it for official duties, approval from the head of the competent agency shall be obtained.
| Article 28 (Plans for safe removal and destruction) |
The head of a relevant agency shall establish a plan to safely remove or destroy classified information in case of emergency, and inform employees under his or her jurisdiction of the plan. <Amended on Dec. 31, 2020>
| Article 29 (Control of classified documents) |
The heads of agencies of various levels may separately prepare and operate regulations necessary for the control over the receipt, transmission, reproduction, perusal, removal, etc. of classified documents.
| Article 30 (Transfer of classified information) |
Classified information shall not be transferred to a general document storage facility; provided, this shall not apply where classified information is transferred to a records management institution under Article 33 (2) of the Public Records Management Act and Article 68 of the Enforcement Decree of that Act.
| Article 31 (Notification of classified information holdings) |
| (1) | The heads of agencies of various levels shall investigate the current status of their classified information holdings twice a year and notify the Director of the National Intelligence Service of the findings thereof. <Amended on Jan. 14, 2020> |
| (2) | The current status of classified information holdings investigated and notified under paragraph (1) shall not be disclosed. <Added on Jan. 14, 2020> |
CHAPTER III PROTECTION OF NATIONAL SECURITY FACILITIES AND STATE-PROTECTED EQUIPMENT
| Article 32 (Designation of national security facilities and State-protected equipment) |
| (1) | The Director of the National Intelligence Service may designate facilities, aircraft, ships, and other important equipment as national security facilities or State-protected equipment, respectively, if their destruction, compromise of their functions, or disclosure of classified information thereon would result in substantial strategic or military damage or a cascading disruption of national security. |
| (2) | The Director of the National Intelligence Service shall prepare standards necessary for designating national security facilities and State-protected equipment under paragraph (1) (hereinafter referred to as "designation standards") in consultation with the heads of relevant central administrative agencies, etc. and local governments. <Amended on Dec. 31, 2020> |
| (3) | If the head of the agency supervising the security management status of facilities or equipment important for national security, such as electric power facilities and aircraft, etc. determined by the Director of the National Intelligence Service, deems that the relevant facilities or equipment meet the designation standards, he or she shall request the Director of the National Intelligence Service to designate such facilities or equipment as national security facilities or State-protected equipment under paragraph (1). |
| (4) | Upon receipt of a request for designation under paragraph (3), the Director of the National Intelligence Service shall examine whether the relevant facilities or equipment meet the designation standards, determine whether to designate the relevant facilities or equipment as national security facilities or State-protected equipment, and notify the head of the requesting agency of the results thereof. |
| (5) | The Director of the National Intelligence Service may modify or supplement the designation standards in consultation with the head of an agency supervising the security management status of national security facilities or State-protected equipment designated under paragraphs (1) through (4) (hereinafter referred to as "supervisory agency"). |
[This Article Added on Jan. 14, 2020]
[Previous Article 32 moved to Article 34 <Jan. 14, 2020>]
| Article 33 (Formulation of measures for protection of national security facilities and State-protected equipment) |
| (1) | The Director of the National Intelligence Service shall formulate measures to protect national security facilities and State-protected equipment (hereinafter referred to as "basic protective measures") in order to protect national security facilities and State-protected equipment. |
| (2) | The head of a supervisory agency shall formulate and implement protective measures for national security facilities and State-protected equipment in the fields under his or her jurisdiction (hereinafter referred to as "protective measures by field") in accordance with basic protective measures. |
| (3) | The head of an agency responsible for the management of national security facilities or State-protected equipment (hereinafter referred to as "managing agency") shall formulate and implement detailed protective measures for the relevant facilities and equipment (hereinafter referred to as "detailed protective measures") in accordance with the protective measures by field formulated by the head of a supervisory agency. |
| (4) | The Director of the National Intelligence Service and the head of a supervisory agency may ascertain whether the head of a managing agency is implementing basic protective measures and protective measures by field and may request necessary measures. |
| (5) | The Director of the National Intelligence Service may request the head of a managing agency to provide necessary data in order to establish basic protective measures. |
| (6) | The Director of the National Intelligence Service shall determine detailed matters necessary for the establishment and implementation of protective measures by field and detailed protective measures. |
[This Article Added on Jan. 14, 2020]
[Previous Article 33 moved to Article 36 <Jan. 14, 2020>]
| Article 34 (Protected areas) |
| (1) | The heads of agencies of various levels and the heads of managing agencies, etc. may designate protected areas within a specified range at locations necessary to protect personnel, documents, materials, and facilities related to national security. <Amended on Jan. 14, 2020> |
| (2) | Protected areas established under paragraph (1) shall be divided into restricted areas, restricted zones, and controlled zones according to their degree of significance. <Amended on Jan. 14, 2020> |
| (3) | Any person who intends to access or enter a protected area shall obtain approval from the heads of agencies of various levels or the head of a managing agency, etc. <Amended on Jan. 14, 2020> |
| (4) | Any person who manage a protected area may restrict or prohibit access to or entry into the protected area by persons who have not obtained approval under paragraph (3). <Amended on Jan. 14, 2020> |
[Title Amended on Jan. 14, 2020]
[Moved from Article 32; Previous Article 34 moved to Article 37 <Jan. 14, 2020>]
| Article 35 (Security assessment) |
| (1) | The Director of the National Intelligence Service shall assess the security of national security facilities, State-protected equipment, and protected areas in order to prevent security incidents. |
| (2) | The security assessment under paragraph (1) shall be conducted ex officio by the Director of the National Intelligence Service or at the request of the head of the relevant agency. <Amended on Dec. 31, 2020> |
| (3) | The Director of the National Intelligence Service may request necessary cooperation from related agencies for security assessment. |
| (4) | Details necessary for the procedures, details, etc. of the security assessment shall be determined by the Director of the National Intelligence Service. |
[This Article Wholly Amended on Jan. 14, 2020]
| Article 35-2 (Handling of security measurement findings) |
| (1) | The Director of the National Intelligence Service shall notify the head of the relevant agency of security assessment findings and improvement measures. <Amended on Dec. 31, 2020> |
| (2) | The head of the relevant agency who has been notified of the security assessment findings and improvement measures under paragraph (1) shall faithfully implement them. <Amended on Dec. 31, 2020> |
| (3) | The Director of the National Intelligence Service and the heads of agencies of various levels may ascertain whether the heads of managing agencies are implementing improvement measures under paragraph (1) and request them to take necessary measures. |
[This Article Wholly Amended on Jan. 14, 2020]
[Moved from Article 37 <Jan. 14, 2020>]
CHAPTER IV BACKGROUND INVESTIGATION
| Article 36 (Background investigation) |
| (1) | The Director of the National Intelligence Service shall conduct a background investigation to verify the loyalty, reliability, etc. of a person falling under subparagraph 2 of Article 3. <Amended on Dec. 31, 2020> |
| (2) | Deleted. <2020. 12. 31.> |
| (3) | The head of a relevant agency shall request the Director of the National Intelligence Service to conduct a background investigation of the following persons: <Amended on Jan. 14, 2020; Dec. 31, 2020> |
| 1. | Persons who are expected to be appointed as public officials (limited to persons who are expected to be appointed to positions handling State secret limited to national security); |
| 2. | Persons to be granted security clearances; |
| 3. | Deleted; <Jan. 14, 2020> |
| 4. | The head of an agency, etc. that manages national security facilities or State-protected equipment (including employees under his or her jurisdiction, who perform the duties of managing the relevant national security facilities, etc.); |
| 5. | Deleted; <Dec. 31, 2020> |
| 6. | Other persons prescribed by other statutes or regulations or persons deemed necessary by the heads of agencies of various levels for national security. |
[Moved from Article 33; Previous Article 36 Deleted. <Jan. 14, 2020>]
| Article 37 (Handling of findings of background investigation) |
| (1) | Upon discovering information that is likely to pose a threat to national security in the course of a background investigation of a person, the Director of the National Intelligence Service shall notify the relevant agency of such fact. |
| (2) | The heads of the relevant agencies in receipt of notification under paragraph (1) shall prepare necessary security measures based on the findings of the background investigation. |
[Title Amended on Jan. 14, 2020]
[Moved from Article 34; Previous Article 37 moved to Article 35-2 <Jan. 14, 2020>]
CHAPTER V SECURITY INVESTIGATION
| Article 38 (Security incident investigations) |
If any of the following incidents occurs, the Director of the National Intelligence Service shall conduct a security incident investigation to ascertain the cause of the incident and to prepare measures to prevent recurrence:
| 1. | Divulgence or loss of classified information; |
| 2. | Destruction of national security facilities or State-protected equipment or infringement of their functions; |
| 3. | Access to or entry into a protected area without approval under Article 34 (3); |
| 4. | Other incidents equivalent to those referred to in subparagraphs 1 through 3, as determined by the Director of the National Intelligence Service. |
[This Article Wholly Amended on Jan. 14, 2020]
| Article 38-2 (Handling of findings from security incident investigations) |
| (1) | The Director of the National Intelligence Service shall notify the head of the relevant agency of the findings from a security incident investigation under Article 38. |
| (2) | The head of an agency in receipt of the findings from a security incident investigation under paragraph (1) shall take necessary measures in connection with the investigation findings, and notify the Director of the National Intelligence Service of the results of the measures taken. |
[This Article Added on Jan. 14, 2020]
CHAPTER VI SECURITY AUDIT OF CENTRAL ADMINISTRATIVE AGENCY, ETC.
| Article 39 (Security audit) |
The head of a central administrative agency, etc. shall conduct a security audit to investigate the status of security management of personnel, documents, materials, facilities, areas, equipment, etc. prescribed in this Decree and whether such status is appropriate. <Amended on Dec. 31, 2020>
| Article 40 (Information and communications security audit) |
The head of a central administrative agency, etc. shall conduct an information and communications security audit to prevent the divulgence of classified information by information and communications means and to investigate the security status of information and communications facilities. <Amended on Dec. 31, 2020>
| Article 41 (Implementation of audit) |
| (1) | Security audits under Article 39 and information and communications security audits under Article 40 shall be classified into regular audits and occasional audits. |
| (2) | Regular audits shall be conducted once a year, and occasional audits shall be conducted from time to time as necessary. |
| (3) | In conducting a security audit and information and communications security audit, the focus shall be on discovering security vulnerabilities or matters requiring improvement. |
| Article 42 (Handling of security audit findings) |
| (1) | The head of a central administrative agency, etc. shall notify the Director of the National Intelligence Service of the findings of security audit under Article 39 and the information and communications security audit under Article 40. <Amended on Dec. 31, 2020> |
| (2) | If the head of a central administrative agency, etc. confirms vulnerabilities in security or matters necessary for improvement in connection with the findings of the security audit under Article 39 and the information and communications security audit under Article 40, he or she shall take measures necessary for preventing recurrence and improvement and notify the Director of the National Intelligence Service of the results of such measures. <Amended on Dec. 31, 2020> |
[This Article Wholly Amended on Jan. 14, 2020]
CHAPTER VII SUPPLEMENTARY PROVISIONS
| Article 43 (Security officer) |
The heads of agencies of various levels shall appoint a security officer to perform security services under this Decree from among their employees.
| Article 44 (Security of martial law areas) |
| (1) | Notwithstanding this Decree, the martial law commander may take special security measures for the security of an area where martial law has been declared. |
| (2) | If the martial law commander intends to take special security measures under paragraph (1), he or she shall have a prior consultation with the Director of the National Intelligence Service when he or she deems it necessary in consideration of the linkage with security services in ordinary times. |
| Article 45 (Entrustment of authority) |
| (1) | The Director of the National Intelligence Service may entrust part of his or her authority related to background investigation under Article 36 to the Minister of National Defense and the Commissioner General of the National Police Agency. <Amended on Jan. 14, 2020; Dec. 31, 2020> |
| (2) | The Director of the National Intelligence Service may, if deemed necessary, entrust part of his or her authority related to security assessment under Article 35 and security incident investigations under Article 38 to the heads of agencies of various levels; provided, the entrustment to the Minister of National Defense shall be limited to security assessment and security incident investigations of the Joint Chiefs of Staff, excluding the Headquarters of the Ministry of National Defense, military units and agencies under the direct control of the Ministry of National Defense, respective armed forces, defense contractors, research institutes under the Defense Acquisition Program Act, and other military security subjects. <Amended on Dec. 31, 2020> |
| (3) | The Director of the National Intelligence Service may, if deemed necessary, request the heads of agencies of various levels entrusted with authority under paragraph (2) to notify the findings of security assessment and security incident investigations. <Amended on Dec. 31, 2020> |
| (4) | The Director of the National Intelligence Service may entrust the heads of relevant central administrative agencies, etc. with the establishment and operation of an integrated classified information management system under Article 21 (3). <Added on Jan. 14, 2020; Dec. 31, 2020> |
| Article 46 (Processing of personally identifiable information) |
| 1. | Business affairs regarding approval of access to and entry into protection areas under Article 34 (3); |
| 2. | Business affairs regarding background investigations under Article 36. |
ADDENDA <Presidential Decree No. 26140, Mar. 11, 2015>
Article 1 (Enforcement date)
This Decree shall enter into force on the date of its promulgation.
Article 2 (Transitional measures concerning security clearances)
If a security clearance has been granted under the previous provisions before this Decree enters into force, it shall be deemed that the security clearance has been granted under the amended provisions of Article 10.
ADDENDA <Presidential Decree No. 28211, Jul. 26, 2017>
Article 1 (Enforcement date)
This Decree shall enter into force on the date of its promulgation; provided, Presidential Decrees amended by Article 8 of the Addenda, which were promulgated before this Decree enters into force but the enforcement dates of which have not arrived yet, shall enter into force on the enforcement date of the respective Decrees.
ADDENDA <Presidential Decree No. 29321, Dec. 4, 2018>
Article 1 (Enforcement date)
This Decree shall enter into force on January 1, 2019.
| (1) | through (11) Omitted. |
ADDENDA <Presidential Decree No. 30352, Jan. 14, 2020>
Article 1 (Enforcement date)
This Decree shall enter into force 1 month after the date of its promulgation.
Article 2 (Applicability to handling of security measurement findings)
The amended provisions of Article 35-2 (3) shall begin to apply where the Director of the National Intelligence Service conducts security assessment after this Decree enters into force. Article 3 (Applicability to handling of findings from security incident investigations)
The amended provisions of Article 38-2 (2) shall begin to apply to cases where the Director of the National Intelligence Service investigates a security incident after this Decree enters into force. Article 4 (Applicability to handling security audit findings)
The amended provisions of Article 42 (2) shall begin to apply where the head of a central administrative agency conducts a security audit or information and communications security audit after this Decree enters into force. Article 5 (Transitional measures concerning national security facilities and State-protected equipment)
Facilities and equipment designated as national security facilities and State-protected equipment as at the time this Decree enters into force shall be deemed national security facilities and State-protected equipment designated under the amended provisions of Article 32, respectively. Article 6 (Transitional measures concerning protected areas)
A protected area established under the previous Article 32 as at the time this Decree enters into force shall be deemed a protected area established under the amended provisions of Article 34.
ADDENDUM <Presidential Decree No. 30833, Jul. 14, 2020>
This Decree shall enter into force on July 15, 2020.
ADDENDA <Presidential Decree No. 30895, Aug. 4, 2020>
Article 1 (Enforcement date)
This Decree shall enter into force on August 5, 2020.
ADDENDA <Presidential Decree No. 31354, Dec. 31, 2020>
Article 1 (Enforcement date)
This Decree shall enter into force on January 1, 2021.
Article 2 (Transitional measures concerning background investigation)
Notwithstanding the amended provisions of Article 36 and the proviso to Article 45 (1), if a background investigation is underway as at the time this Decree enters into force, the background investigation shall be conducted under the previous provisions.