(Unofficial Translation)
No. 136 Chapter 69 Kor
Government Gazette
27 May 2019
In preparing the policy and plan under paragraph one, the Office shall hold a hearing or
meeting with the Government Agency, Supervising or Regulating Organization, and Organization
of Critical Information Infrastructure.
Section 44
The Government Agency, Supervising or Regulating Organization, and
Organization of Critical Information Infrastructure shall prepare a Code of Practice and standard
framework for Maintaining Cybersecurity of each organization in accordance with the policy and
plan on Maintaining Cybersecurity without delay.
The Code of Practice for Maintaining Cybersecurity under paragraph one, at least, shall
consist of the following:
(1) the plan for examining and assessing risks related to Maintaining Cybersecurity
by an examiner, internal auditor, or independent external auditor, at least once per
year;
(2) the plan for coping with Cyber Threats.
For the benefit of preparing the Code of Practice for Maintaining Cybersecurity in
paragraph one, the Office, upon the approval of the Committee, shall prepare a Code of Practice
and standard framework for the Government Agency, Supervising or Regulating Organization, or
Organization of Critical Information Infrastructure to use as a guideline to prepare or exercise as
a Code of Practice of the Government Agency, Supervising or Regulating Organization, or
Organization of Critical Information Infrastructure. In case such organizations do not yet have or
have but incomplete or is not in accordance with the Code of Practice and standard framework,
such Code of Practice and standard framework shall be enforced.
Part 2
Management
Section 45
The Government Agency, Supervising or Regulating Organization, and
Organization of Critical Information Infrastructure have a duty to prevent, cope with, and
mitigate risks from Cyber Threats in accordance with the Code of Practice and standard
framework for Maintaining Cybersecurity of each organization and shall act in order to be in
compliance with the Code of Practice and standard framework for Maintaining Cybersecurity in
accordance with section 13 paragraph one (4).
In case the Government Agency, Supervising or Regulating Organization, or
Organization of Critical Information Infrastructure could not act or comply in accordance with
paragraph one, the Office may grant assistance in the personnel or technological aspects to such
organization as requested.
Section 46
For the benefit of Maintaining Cybersecurity, the Government Agency,
Supervising or Regulating Organization, and Organization of Critical Information Infrastructure
shall notify the name of executive officials and operational officials for the coordination of
Maintaining Cybersecurity to the Office.
In the event there is a change to the officials under paragraph one, the Government
Agency, Supervising or Regulating Organization, and Organization of Critical Information
Infrastructure shall notify the Office without delay.
Section 47 In case the performance of the duties in accordance with this Act requires
knowledge and expertise, the Committee or the CRC may assign the Secretary-General to hire an
expert as appropriate for each specific task.
13