(Unofficial Translation)
No. 136 Chapter 69 Kor
Government Gazette
27 May 2019
at a critical level, the CRC shall issue an order to the Office to perform the following:
(1) gather information, or relevant documentary evidence, witness, material evidence
to analyze the situation, and evaluate the effects from Cyber Threats;
(2) support, assist, and participate in the prevention, coping with, and mitigation of
risks from Cyber Threats;
(3) prevent Cybersecurity Incidents which occurred from Cyber Threats, suggest or
issue an order to use the solution system to maintain cybersecurity, including
finding the approach for countermeasure or solution regarding cybersecurity;
(4) support such that the Office and the relevant organizations, both the public and
private sector, to provide assistance and participate in the prevention, coping with,
and mitigation of risks from the Cyber Threats occurred;
(5) notify of the Cyber Threat to be informed in general, as necessary and appropriate,
taking into consideration the situation, severity, and effect from such Cyber Threat;
(6) facilitate in coordinating between relevant Government Agency and private
organization to deal with risks and incidents related to cybersecurity.
Section 62
In operations in accordance with section 61, for the benefit of analyzing
the situation and evaluating the effects from Cyber Threats, the Secretary-General shall order the
Competent Officials to:
(1) issue a letter requesting cooperation from the relevant persons to provide
information within an appropriate period and at the prescribed place, or provide
information in writing related to the Cyber Threat;
(2) issue a letter requesting for information, documents, or copy of the information or
documents in the possession of other person which is beneficial to the operation;
(3) inquire the persons who has knowledge and understanding of the facts and
situations which are related to the Cyber Threat;
(4) enter into a property or place of business which is or may be related to the Cyber
Threat of a related person or organization, with consent from the person in
possession of such place.
Any person providing information in accordance with paragraph one, which acts in good
faith, shall receive protection and shall not be deemed a wrongful act or a breach of a contract.
Section 63
In case of necessity to prevent, cope with, and mitigate risks from a
Cyber Threat, the CRC shall order the Government Agency to provide information, support its
personnel, or use electronic devices under its possession in relation to Maintaining Cybersecurity.
The CRC shall ensure that there shall be no use of information under paragraph one that
may cause damages and the CRC is responsible for the compensation for the personal, expenses,
damages occurred from the use of such electronic devices.
Paragraph one and two shall also be applied to the requests to private organization, upon
the consent of such private organization.
Section 64
In case there is or may be a Cyber Threat at a critical level, the CRC
shall prevent, cope with, and mitigate risks from the Cyber Threat and conduct necessary
measures.
In the operation under paragraph one, the CRC shall issue a letter to the Government
Agency which relates to Maintaining Cybersecurity to act or omit any act to prevent, cope with,
or mitigate risks from the Cyber Threat properly and efficiently, in accordance with the guideline
prescribed by the CRC, including integrating the operation to control, terminate, or mitigate the
18