CHAPTER TWO
ACTIVITIES TO ENSURE CYBER SECURITY
Article 6.Workstreams in ensuring cyber security
6.1.The work of ensuring cyber security shall consist of the following workstreams:
6.1.1.policy, administration, facilitation;
6.1.2.technical and technological measures to ensure cyber security;
6.1.3.prevention from, and promoting awareness of cyber-attacks and violations;
6.1.4.detection, termination of, and responding to cyber-attacks and violations,
restorative measures..
Article 7.Common procedures to ensure cyber security
7.1.The Government shall adopt the common procedures on ensuring cyber security, prevention,
detection and counter-responses.
7.2.The legal persons stipulated in articles 16.1, 17.1, and 19.1 of this law shall have its internal
procedure in ensuring cyber security that conforms to the common procedure to ensure cyber security.
Article 8.Cyber security risk assessment
8.1.Cyber security risk assessment shall be conducted by legal persons registered at the state
central administrative organization in charge of digital development and communications.
8.2.The legal person stipulated in article 8.1 of this law shall have an employee on staff that has
been certified by an international professional or standards association, or an equivalent organization.
8.3.The state central administrative organization in charge of digital development and
communications and the intelligence agency shall jointly adopt the procedures and methodology for
conducting cyber security risk assessment.
8.4.The intelligence agency, or by the permission thereof a legal person stipulated in article 8.1 of
this law shall conduct the cyber security risk assessment of organizations connected to the state
information consolidated network, and of state-owned legal persons with critical information infrastructure.
8.5.The legal persons stipulated in article 8.1 of this law, and the relevant organization and official
who have received the cyber security risk assessment report shall be obligated to maintain the
confidentiality and ensure non-disclosure thereof.
Article 9.Information security audit
9.1.Information security audits shall be conducted by legal persons registered with the state
central administrative organization in charge of digital development and communications.
9.2.The following requirements shall be met by legal persons to conduct information security
audits:
9.2.1. Have an employee on staff that has been certified by an international professional
or standards association, or an equivalent organization to conduct information security audits;
9.2.2.The employee stipulated in article 9.2.1 of this law shall not maintain simultaneous
employment with other legal person authorized to conduct audits of the same type;
9.2.3.Other requirements stipulated in the law.
9.3.It shall be prohibited for a legal person conducting information security audit to conduct