Amendments to the Information and Communications Network Act and its enforcement decree—which impose fines of up to 3% of relevant revenue on companies that repeatedly suffer cyber incidents and elevate the Chief Information Security Officer (CISO) to executive-level status—will take effect on October 1. The Ministry of Science and ICT announced this on September 30 and explained that the information security system will be comprehensively strengthened, covering everything from incident prevention to post-incident response and sanctions.
The implementation of these laws and regulations is intended to institutionally support the comprehensive inter-ministerial information security measures announced in response to a series of major security breaches last year. The President has previously directed, during meetings with senior advisors and other forums, that the government prepare strong countermeasures—including punitive fines—against companies that repeatedly experience security incidents and consider conducting preemptive investigations. The Information and Communications Network Act, amended last March, includes provisions to secure substantive authority for Chief Information Security Officers (CISOs), mandate the establishment of information security committees, introduce enhanced Information Security Management System (ISMS) certification, expand the government’s authority to conduct ex officio investigations, increase fines for late reporting, and establish new enforcement penalties and administrative fines. The enforcement decree specifies the details delegated by the Act.
First, the status of the CISO is elevated from that of a regular employee to an executive officer. Mid-sized companies and similar entities must designate a CISO as an executive officer, while small and medium-sized enterprises (SMEs) may, as they do now, designate the head of an information security-related department, taking into account the company’s size and staffing circumstances. A six-month grace period is granted to companies required to designate a new executive officer.
Companies subject to the CISO reporting requirement must establish and operate an in-house Information Security Committee. Chaired by the CISO, the committee consists of heads of key departments—such as IT development, personal information protection, human resources, and finance—and deliberates on matters requiring company-wide consultation, such as securing information security budgets and personnel. The results of these deliberations must be reported to the CEO, and major issues must also be reported to the board of directors.
In the event of a security breach, a new “enhanced ISMS certification” requirement will apply to businesses whose operations have a significant impact on the public. This applies to major information and communications service providers—such as telecommunications companies—with annual revenue of 1 trillion won or more in the previous year, operators of integrated information and communications facilities, information and communications service providers with annual revenue of 3 trillion won or more, and businesses that have been subject to an investigation by a joint public-private investigation team or imposed with administrative fines within the last three years. The certification audit process will be revised to include both document reviews and on-site inspections, and technical audits—such as vulnerability assessments—will be added for businesses subject to the enhanced certification and those that have experienced security incidents.
Investigations and sanctions will also be strengthened. If evidence of a security breach is secured, the Security Incident Investigation Deliberation Committee—affiliated with the Ministry of Science and ICT and tasked with deliberating on the need for a prompt government investigation—will be formally activated. The committee will consist of 15 members from the private and public sectors, including the chairperson, and private-sector members will serve two-year terms. Businesses that fail to comply with government corrective orders or requests for information will be subject to a compliance penalty equivalent to 0.02% of their average daily revenue for each day of noncompliance. Businesses that repeatedly cause security incidents through willful misconduct or gross negligence will be subject to administrative fines ranging up to 3% of relevant revenue, depending on the severity of the incident.
Deputy Prime Minister and Minister of Science and ICT Bae Kyung-hoon stated, “With the enforcement of the Information and Communications Network Act and its Enforcement Decree, we have established an institutional foundation that will further strengthen corporate security awareness and accountability,” and “We expect companies to recognize security not merely as a cost but as an essential element of business management and to proceed with proactive investment. The government will also actively support the successful implementation of this system to create a digital environment that the public can use with confidence,” he added.




![[인터뷰] 심리 상담사가 직접 말하는 심리 상담사의 하루](https://en.swn.kr/wp-content/uploads/sites/24/2015/07/KakaoTalk_20141219_092335502.jpg)