(Unofficial Translation) No. 136 Chapter 69 Kor Government Gazette 27 May 2019 Section 40 The Cabinet shall have the power to generally supervise the operation of the Office in accordance with the duties and powers of the Office, the laws, national strategies, policies and plans of the government, and relevant Cabinet resolutions. In the light of this, the Cabinet shall have the power to order the Secretary-General to clarify facts, comment, or prepare the report, and cease operations of the Office that are against the duties and powers of the Office, the laws, national strategies, policies and plans of the government, or the relevant Cabinet resolutions, including to order an investigation of the facts regarding operations of the Office. Chapter 3 Maintaining Cybersecurity Part 1 Policies and plans Section 41 Maintaining Cybersecurity shall take into consideration the unity and integration of the operation of Government Agencies and private organizations, and shall align with the national policy and plan regarding the digital development for economy and society in accordance with the laws regarding the digital development for economy and society, and the policy and master plan which are related to maintaining the security of the National Security Council. The operation on Maintaining Cybersecurity shall aim to create the capability to prevent, cope with, and mitigate risks from Cyber Threats, especially in protecting the Critical Information Infrastructure of the country. Section 42 The policy and plan on Maintaining Cybersecurity shall at least contain the following objectives and approaches: (1) (2) (3) (4) (5) (6) (7) (8) integration of management in Maintaining Cybersecurity of the country; establishment of measures and mechanisms to develop capability to prevent, cope with, and mitigate the risks from Cyber Threats; establishment of measures to protect the Critical Information Infrastructure of the country; cooperation between the public and private sector, and international cooperation for Maintaining Cybersecurity; research and development of technology and knowledge related to Maintaining Cybersecurity; development of personnel and experts in Maintaining Cybersecurity, both in the public and the private sector; creation of awareness and knowledge in Maintaining Cybersecurity; development of rules and laws for Maintaining Cybersecurity. Section 43 The Committee shall prepare a policy and plan for Maintaining Cybersecurity in accordance with section 42 to propose to the Cabinet for approval, which shall be published in the Government Gazette. Once published, Government Agencies, Supervising or Regulating Organizations, and Organizations of Critical Information Infrastructure as determined in the plan on Maintaining Cybersecurity shall take action to be in accordance with such policy and plan. 12

Select target paragraph3