(Unofficial Translation) No. 136 Chapter 69 Kor Government Gazette 27 May 2019 Infrastructure shall notify the name and contact information of the owner, the person possessing the computer, and the person monitoring the computer system to the Office, its Supervising or Regulating Organization, and the organization under section 50, within thirty days from the date the Committee prescribes the notification in accordance with section 49 paragraph two and section 50 paragraph two, or from the date the Committee issues a final judgement in accordance with section 51, as the case may be; the owner, the person possessing the computer, and the person monitoring the computer system shall at least be a person responsible for the management of such Organization of Critical Information Infrastructure. In case there is any change to the owner, the person possessing the computer and the person monitoring the computer system in accordance with paragraph one, notice of change to the relevant organizations under paragraph one shall be given not less than seven days in advance, unless there is reasonable cause which is inevitable, it shall be notified without delay. Section 53 In the operation of Maintaining Cybersecurity of the Organization of Critical Information Infrastructure, the Supervising or Regulating Organization shall examine the minimum cybersecurity standard of the Organization of Critical Information Infrastructure under its supervision. If found that Organization of Critical Information Infrastructure does not comply with the standards, the Supervising or Regulating Organization shall notify the Organization of Critical Information Infrastructure which is below the standards to make correction in order to meet the standards without delay. If such Organization of Critical Information Infrastructure neglects or fails to comply within the period prescribed by the Supervising or Regulating Organization, the Supervising or Regulating Organization shall notify the CRC for consideration without delay. Upon receipt of notification under paragraph one, if the CRC considers and views that there is such reason and which may cause a Cyber Threat, the CRC may perform the following: (1) in case of a Government Agency, the CRC shall notify the chief executive of the agency to exercise executive power to issue an order to the Government Agency or the Organization of Critical Information Infrastructure to correct and comply with the standards without delay; (2) in case of a private organization, the CRC shall notify the chief executive of the organization, the person possessing the computer, and the person monitoring the computer system of the Organization of Critical Information Infrastructure to make correction and comply with the standards without delay. The Secretary-General shall monitor to ensure compliance of paragraph two. Section 54 The Organization of Critical Information Infrastructure shall conduct risk assessment on Maintaining Cybersecurity by having an examiner, including examination in the cybersecurity aspect by the information security auditor, internal auditor or external independent auditor, at least once per year. The Organization of Critical Information Infrastructure shall submit a summary report of the operation result to the Office within thirty days after the operation has been finished. Section 55 In case the CRC views that the risk assessment on Maintaining Cybersecurity or the examination in the cybersecurity aspect in accordance with section 54 is not in compliance with the standards according to the report of the Supervising or Regulating Organization, the CRC shall order the Organization of Critical Information Infrastructure to conduct the risk assessment again to be in accordance with the standards, or proceed with the examination in other aspects that may affect the Critical Information Infrastructure. In case the Organization of Critical Information Infrastructure has already conducted the 15

Select target paragraph3