(Unofficial Translation) No. 136 Chapter 69 Kor Government Gazette 27 May 2019 effect caused by the Cyber Threat in a timely manner. The Secretary-General shall report the operation in accordance with this Section to the CRC constantly and when such Cyber Threat ends, the Secretary-General shall report the operation result to the CRC without delay. Section 65 In coping with and to remedy the damages from a Cyber Threat at a critical level, the CRC has the power to order, only as necessary to prevent the Cyber Threat, the owner, the person possessing the computer, or the user of a computer or a computer system or a person monitoring the computer system, which has a reasonable cause to believe that he/she is related to the Cyber Threat or is affected by the Cyber Threat to conduct the following acts: (1) monitor the computer or computer system during a certain period of time; (2) examine the computer or computer system to find an error that affects Maintaining Cybersecurity, analyze the situation, and evaluate the effects from the Cyber Threat; (3) conduct a measure rectifying the Cyber Threat to handle vulnerabilities or remove unwanted programs or terminate and remedy the Cyber Threat that are operating; (4) maintain the status of the computer data or computer system via any methods to operate the computer forensic science; (5) access relevant computer data or computer system or other information related to the computer system only to the extent it is necessary to prevent Cyber Threat. In case of necessity to access information under (5), the CRC shall assign the SecretaryGeneral to submit the motion to the Competent Court to order the owner, the person possessing the computer, the user of the computer or computer system or a person monitoring the computer system in accordance with paragraph one to comply with the motion. The motion submitted to the Court shall specify the cause to believe that a person is performing or will perform an act that cause Cyber Threat in a critical level. The motion shall be submitted as emergency hearing motion and shall be considered by the Court without delay. Section 66 In preventing, coping with, or mitigating the risks from Cyber Threats in a critical level, the CRC has the power to order a Competent Official, only to the extent that it is necessary to prevent the Cyber Threat, to do the following: (1) enter into a place to examine, with a letter informing the appropriate reason to the owner or the occupier to examine such place. If there is a cause to believe that there is a computer or computer system related to the Cyber Threat or is affected from the Cyber Threat; (2) access the computer data, computer system, or other data related to the computer system, copy, or filter/screen information data or computer program which has a reason to believe that is related to or affected by the Cyber Threat; (3) test the operation of the computer or computer system which has a reason to believe that is related to or affected by the Cyber Threat or has been used to search any information from the inside or taking advantage of the computer or computer system; (4) seize or freeze a computer, a computer system, or any equipment, only to the extent it is necessary, which has a reason to suspect that is related to the Cyber Threat for the examination or analysis, for not more than thirty days. Once such period is over, computer or any equipment shall be returned to the owner or the person possessing the computer immediately after the examination or analysis is finished. In operating in accordance with (2), (3), and (4), the CRC may submit a motion to the Competent Court to order the officers to comply with the motion. The motion submitted to the 19

Select target paragraph3