(Unofficial Translation) No. 136 Chapter 69 Kor Government Gazette 27 May 2019 In preparing the policy and plan under paragraph one, the Office shall hold a hearing or meeting with the Government Agency, Supervising or Regulating Organization, and Organization of Critical Information Infrastructure. Section 44 The Government Agency, Supervising or Regulating Organization, and Organization of Critical Information Infrastructure shall prepare a Code of Practice and standard framework for Maintaining Cybersecurity of each organization in accordance with the policy and plan on Maintaining Cybersecurity without delay. The Code of Practice for Maintaining Cybersecurity under paragraph one, at least, shall consist of the following: (1) the plan for examining and assessing risks related to Maintaining Cybersecurity by an examiner, internal auditor, or independent external auditor, at least once per year; (2) the plan for coping with Cyber Threats. For the benefit of preparing the Code of Practice for Maintaining Cybersecurity in paragraph one, the Office, upon the approval of the Committee, shall prepare a Code of Practice and standard framework for the Government Agency, Supervising or Regulating Organization, or Organization of Critical Information Infrastructure to use as a guideline to prepare or exercise as a Code of Practice of the Government Agency, Supervising or Regulating Organization, or Organization of Critical Information Infrastructure. In case such organizations do not yet have or have but incomplete or is not in accordance with the Code of Practice and standard framework, such Code of Practice and standard framework shall be enforced. Part 2 Management Section 45 The Government Agency, Supervising or Regulating Organization, and Organization of Critical Information Infrastructure have a duty to prevent, cope with, and mitigate risks from Cyber Threats in accordance with the Code of Practice and standard framework for Maintaining Cybersecurity of each organization and shall act in order to be in compliance with the Code of Practice and standard framework for Maintaining Cybersecurity in accordance with section 13 paragraph one (4). In case the Government Agency, Supervising or Regulating Organization, or Organization of Critical Information Infrastructure could not act or comply in accordance with paragraph one, the Office may grant assistance in the personnel or technological aspects to such organization as requested. Section 46 For the benefit of Maintaining Cybersecurity, the Government Agency, Supervising or Regulating Organization, and Organization of Critical Information Infrastructure shall notify the name of executive officials and operational officials for the coordination of Maintaining Cybersecurity to the Office. In the event there is a change to the officials under paragraph one, the Government Agency, Supervising or Regulating Organization, and Organization of Critical Information Infrastructure shall notify the Office without delay. Section 47 In case the performance of the duties in accordance with this Act requires knowledge and expertise, the Committee or the CRC may assign the Secretary-General to hire an expert as appropriate for each specific task. 13

Select target paragraph3