(Unofficial Translation) No. 136 Chapter 69 Kor Government Gazette 27 May 2019 Office of the National Cybersecurity Committee Section 20 There shall be an Office of the National Cybersecurity Committee as a Government Agency who is a juristic person and not a government sector entity under the laws governing the administration or a state enterprise under the law on budget procedures or other laws. Section 21 The operation of the Office is not regulated by the labor protection law, labor relation law, social security law, and compensation fund law. However, officers and employees of the Office shall receive compensation not less than that specified under the labor protection law, social security law, and compensation fund law. Section 22 The Office shall be responsible for administrative, academic, meeting, and secretarial tasks of the Committee and the CRC, and shall also have the duties and powers to: (1) suggest and support preparation of the policy and plan on Maintaining Cybersecurity and the operational plan for Maintaining Cybersecurity in accordance with section 9 to the Committee; (2) prepare the Code of Practice and standard framework in Maintaining Cybersecurity in accordance with section 13 paragraph one (4), proposed to the CRC for the approval; (3) coordinate the acts of Maintaining Cybersecurity of Organization of Critical Information Infrastructure in accordance with section 53 and section 54; (4) coordinate and cooperate in the establishment of coordinating agencies for Maintaining Cybersecurity in the country and foreign countries with respect to Cybersecurity Incidents and determining Cybersecurity Solutions; (5) act and coordinate with the Government Agency and private organizations in order to respond and cope with the Cyber Threats as assigned by the Committee; (6) monitor the risk of occurrence of Cyber Threats, follow, analyze, and process information in relation to the Cyber Threats and the alerts on the Cyber Threats; (7) perform, coordinate, support, and assist relevant agencies in complying with the policy and plan on Maintaining Cybersecurity, the operational plan for Maintaining Cybersecurity, and the measures to prevent, cope with, and mitigate the risks at Cyber Threats or as ordered by the Committee; (8) act and cooperate or assist in preventing, coping with, and mitigating the risks of Cyber Threats, especially Cyber Threats that affect or occur in relation to the Critical Information Infrastructure; (9) strengthen the knowledge and understanding in Maintaining Cybersecurity, including to create awareness of the incidents regarding the Cyber Threats in order to have a practical operation in a manner that is integrated and up-to-date; (10) act as central point of collection and analysis of data regarding Maintaining Cybersecurity of the country, and disseminating the information related to cybersecurity risks and incidents to Government Agencies and private organizations; (11) act as the central coordinator between the institution regarding Maintaining Cybersecurity of Government Agencies and private organizations, both in the country and in foreign countries; (12) make agreements and cooperate with organizations or institutions both in the country and in foreign countries for the operation in accordance with the duty and power of the Office, upon receiving approval from the Committee; 7

Select target paragraph3