(Unofficial Translation)
No. 136 Chapter 69 Kor
Government Gazette
27 May 2019
Infrastructure shall notify the name and contact information of the owner, the person possessing
the computer, and the person monitoring the computer system to the Office, its Supervising or
Regulating Organization, and the organization under section 50, within thirty days from the date
the Committee prescribes the notification in accordance with section 49 paragraph two and
section 50 paragraph two, or from the date the Committee issues a final judgement in accordance
with section 51, as the case may be; the owner, the person possessing the computer, and the
person monitoring the computer system shall at least be a person responsible for the management
of such Organization of Critical Information Infrastructure.
In case there is any change to the owner, the person possessing the computer and the
person monitoring the computer system in accordance with paragraph one, notice of change to the
relevant organizations under paragraph one shall be given not less than seven days in advance,
unless there is reasonable cause which is inevitable, it shall be notified without delay.
Section 53
In the operation of Maintaining Cybersecurity of the Organization of
Critical Information Infrastructure, the Supervising or Regulating Organization shall examine the
minimum cybersecurity standard of the Organization of Critical Information Infrastructure under
its supervision. If found that Organization of Critical Information Infrastructure does not comply
with the standards, the Supervising or Regulating Organization shall notify the Organization of
Critical Information Infrastructure which is below the standards to make correction in order to
meet the standards without delay. If such Organization of Critical Information Infrastructure
neglects or fails to comply within the period prescribed by the Supervising or Regulating
Organization, the Supervising or Regulating Organization shall notify the CRC for consideration
without delay.
Upon receipt of notification under paragraph one, if the CRC considers and views that
there is such reason and which may cause a Cyber Threat, the CRC may perform the following:
(1) in case of a Government Agency, the CRC shall notify the chief executive of the
agency to exercise executive power to issue an order to the Government Agency or
the Organization of Critical Information Infrastructure to correct and comply with
the standards without delay;
(2) in case of a private organization, the CRC shall notify the chief executive of the
organization, the person possessing the computer, and the person monitoring the
computer system of the Organization of Critical Information Infrastructure to make
correction and comply with the standards without delay.
The Secretary-General shall monitor to ensure compliance of paragraph two.
Section 54
The Organization of Critical Information Infrastructure shall conduct risk
assessment on Maintaining Cybersecurity by having an examiner, including examination in the
cybersecurity aspect by the information security auditor, internal auditor or external independent
auditor, at least once per year.
The Organization of Critical Information Infrastructure shall submit a summary report of
the operation result to the Office within thirty days after the operation has been finished.
Section 55
In case the CRC views that the risk assessment on Maintaining
Cybersecurity or the examination in the cybersecurity aspect in accordance with section 54 is not
in compliance with the standards according to the report of the Supervising or Regulating
Organization, the CRC shall order the Organization of Critical Information Infrastructure to
conduct the risk assessment again to be in accordance with the standards, or proceed with the
examination in other aspects that may affect the Critical Information Infrastructure.
In case the Organization of Critical Information Infrastructure has already conducted the
15