(Unofficial Translation)
No. 136 Chapter 69 Kor
Government Gazette
27 May 2019
risk assessment on Maintaining Cybersecurity or examination in the cybersecurity aspect of
paragraph one but the CRC views that it is not in compliance with the standards, CRC may
perform the following:
(1) in case of a Government Agency, the CRC shall notify the chief executive of the
agency to exercise executive power to issue an order to the Government Agency or
Organization of Critical Information Infrastructure to correct and comply with the
standards without delay;
(2) in case of a private organization, the CRC shall notify the chief executive of the
organization, the person possessing the computer, and the person monitoring the
computer system of the Organization of Critical Information Infrastructure to make
correction and comply with the standards without delay.
The Secretary-General shall monitor to ensure compliance of paragraph two.
Section 56
The Organization of Critical Information Infrastructure shall establish a
mechanism or process to monitor Cyber Threats or Cybersecurity Incidents which relates to its
Critical Information Infrastructure in accordance with the standards as determined by the
Supervising or Regulating Organization and in accordance with Code of Practice, including the
system of Cybersecurity Solution as determined by the Committee or the CRC, and shall
participate in the assessment on the readiness in coping with Cyber Threats as held by the Office.
Section 57
In the event of a Cyber Threat significantly occurring to the system of
the Organization of Critical Information Infrastructure, the Organization of Critical Information
Infrastructure shall report to the Office and the Supervising or Regulating Organization and cope
with the Cyber Threats as prescribed in Part 4, the CRC may prescribe criteria and method of the
reporting.
Part 4
Coping with Cyber Threats
Section 58
In the case there is or may be a Cyber Threat to an information system
that is under the responsibility of a Government Agency or an Organization of Critical
Information Infrastructure, such organization shall examine its related information, computer
data, and the computer system, including the surrounding circumstances to assess whether a
Cyber Threat has occurred. If the examination results show that there is or may be a Cyber
Threat, the organization shall prevent, cope with, and mitigate the risks from such Cyber Threat
in accordance with the Code of Practice and standard framework in Maintaining Cybersecurity
and shall notify the Office and its Supervising or Regulating Organization without delay.
In case the agency or organization, or any person, finds an obstacle or issues in
preventing, coping with, or mitigating the risks from a Cyber Threat, such agency, or organization
or person may request assistance from the Office.
Section 59
When it appears to the Supervising or the Regulating Organization, or
when the Supervising or the Regulating organization is notified of an incident in accordance with
section 58, the Supervising or Regulating Organization in cooperation with the organization
under section 50 shall gather information, examine, analyze the situation, and evaluate the effects
related to the Cyber Threat and shall perform the following:
(1) support and grant assistance to the Government Agency or Organization of Critical
16