(Unofficial Translation) No. 136 Chapter 69 Kor Government Gazette 27 May 2019 Section 9 The Committee shall have the following duties and powers to: (1) propose the policy and plan on Maintaining Cybersecurity, promote, and support the act of Maintaining Cybersecurity in accordance with section 42 and section 43 for the Cabinet's approval, which shall be in accordance with the guideline specified under section 42; (2) determine management policy for Maintaining Cybersecurity for the Government Agency and Organization of Critical Information Infrastructure; (3) prepare the operational plan for Maintaining Cybersecurity to propose to the Cabinet as a master plan for Maintaining Cybersecurity under general situations and situations where the Cyber Threats may occur or have occurred; such plan shall be in accordance with the policy, strategy, and national plan as well as the policy framework and master plan which are related to maintaining the security of the National Security Council; (4) establish the standard and guideline to enhance and develop service systems pertaining to Maintaining Cybersecurity, establish the standard in respect of Maintaining Cybersecurity, and determine the minimum standard pertaining to a computer, computer system, computer program, as well as support the certifying of standards for Maintaining Cybersecurity of Organization of Critical Information Infrastructure, Government Agency, Supervising or Regulating Organization, and private organizations; (5) prescribe measures and guidelines to enhance the knowledge and expertise in Maintaining Cybersecurity of the Competent Officials, officers of the Organization of Critical Information Infrastructure, Government Agency, Supervising or Regulating Organization, and private organizations which are related to Maintaining Cybersecurity; (6) set out a framework on coordinating with other agencies, both in the country and foreign countries, which are related to Maintaining Cybersecurity; (7) appoint and remove the Secretary-General; (8) assign the supervision and regulation, including the issuing of regulations, objectives, duties and power, and the operational framework regarding Maintaining Cybersecurity to the Supervising or Regulating Organization, Government Agency, or the Organization of Critical Information Infrastructure. (9) monitor and evaluate the results of operating in accordance with the policy and plan on Maintaining Cybersecurity, operational plan for Maintaining Cybersecurity, and of Maintaining Cybersecurity as specified under this Act; (10) suggest and provide opinions to the Digital Economy and Society Committee or to the Cabinet on Maintaining Cybersecurity; (11) suggest to the Cabinet the legislation or amendment of laws related to Maintaining Cybersecurity; (12) prepare a summary report of undertakings of Maintaining Cybersecurity that have significant effect, or the approach for developing the standard of Maintaining Cybersecurity for the Cabinet to be informed; (13) perform any other task as specified under this Act or as assigned by the Cabinet. Section 10 The meeting of the Committee shall be in accordance with the rules as determined by the Committee, where the meeting may proceed via electronic means or other means. Section 11 The chairperson and the directors shall receive a meeting allowance or 4

Select target paragraph3