19.1.10.organizations that produce, store, and distribute strategic food stuff; 19.1.11.Information and operational management center; 19.1.12.National public radio and television; 19.1.13.organization in charge of main and supporting information systems and base information databases; 19.1.14.organization in charge of data centers, their branches and resource center operations; 19.1.15.organization in charge of border port control and administration systems; 19.1.16.organization mining minerals of strategic significance; 19.1.17.organization in charge of registration, monitoring, and consolidated information systems relating to passengers and transportation vehicles that are crossing the national borders. 19.2.Organizations with critical information infrastructure shall have the following obligations: 19.2.1.adopt internal procedures for ensuring cyber security; 19.2.2.adopt and implement an action plan in case of cyber-attacks and violations; 19.2.3.introduce standards to ensure information security; 19.2.4. have an officer or unit on staff in charged with ensuring cyber security; 19.2.5. have cyber security risk assessments conducted every year, and where modifications are made to the information systems and information networks have such assessments done partially for each case, and fully if required by the relevant authorities, and take measures in accordance with the conclusion, recommendations, and requirements issued in relation thereto; 19.2.6.have information security audits conducted every two years; 19.2.7.plan and implement management, organizational, and technical measures necessary for ensuring the information system and information network security; 19.2.8.have an information system for the detection, registration, and termination of cyber-attacks and violations; 19.2.9. store information system action log for the time period stipulated in the common procedure for ensuring cyber security; 19.2.10.submit the cyber security risk assessment and information security audit reports to the relevant center against cyber-attacks and violations within one month of receipt; 19.2.11.comply with the requirements issued by the relevant authorities, and take measures to eliminate the violations and errors detected; 19.2.12.If cyber security risk assessments are to be conducted by foreign citizens and foreign legal persons, the intelligence agency shall be consulted; 19.2.13.have an action plan in place for ensuring the normal, uninterrupted operation of the information system and infrastructure, and for restoration thereof in case of damages and interruptions; 19.2.14. notify the relevant center against cyber-attacks and violations immediately of failure of normal, uninterrupted operations of the information systems and infrastructure due to cyber-attacks and violations;

Select target paragraph3