Policy

From Today, Cyber Intrusion Response Tightens After Reporting, with Fees Imposed Even for Delayed Corrective Action

IT DAILY ·

[Photo: AI-generated image]

✦ AI Summary

The revised Network Act and enforcement decree take effect from today.

The Ministry of Science and ICT said the move is meant to provide institutional support for the "comprehensive cross-ministerial information protection measures."

The revised rules include stronger CISO authority, the creation of information protection committees, tougher certification reviews, and expanded responses and sanctions after cyber intrusion incident reporting.

The revised Network Act and enforcement decree take effect on the 1st. The Ministry of Science and ICT said the purpose of the legislation’s implementation is to provide institutional backing for the "comprehensive cross-ministerial information protection measures." The "comprehensive cross-ministerial information protection measures" were drawn up in response to a series of major intrusion incidents last year, and the revised rules have translated those measures into law.

As a result, the implementation of the revised rules is focused on strengthening corporate internal information protection systems. The revised rules strengthen the status of the Chief Information Security Officer (CISO) and provide a legal basis for operating an information protection committee with participation from key departments. The information protection committee is to discuss security budgets and staffing issues, and its deliberation results must be reported to the CEO. Major matters must be reported to the board. Accordingly, the scope of corporate information protection responsibility is expanding from the security organization to management decision-making.

The revised direction is to link security investment decisions, certification reviews, and post-incident corrective action. Accordingly, companies’ management obligations are expanding beyond appointing security officers to include actual operations and improvement measures, and beyond securing certification to include actual operations and improvement measures.

Externally, reporting after cyber intrusion incidents will be strengthened, and expanded government investigation authority and expanded economic sanctions will be introduced together. A new penalty surcharge will be created for repeated intrusion incidents, and fees will be imposed if corrective action is delayed.

Under the revision, there will be direct changes inside companies in the form of a change in CISO status and the establishment of information protection committees. Mid-sized companies and others will be subject to an obligation to designate a CISO as an executive, while small and medium-sized companies may continue to designate the head of an information protection-related department as before. Companies newly subject to the executive designation obligation under this revision will receive a 6-month grace period.

Companies subject to the CISO reporting obligation will also be required to establish and operate an information protection committee. The CISO will serve as chair of the committee. The committee will include heads of key departments such as IT development, personal information protection, human resources, and finance.

The information protection committee will deliberate on securing information protection budgets and staffing, as well as companywide consultation matters. Accordingly, the structure will involve resource allocation and operating departments jointly participating in discussions on security investment resources. The finance department, linked to securing budgets; the human resources department, linked to staffing increases; and the IT development department, linked to security measures in the development process, will all take part.

This structure is meaningful in that it changes the way security issues are handled. Security issues will be addressed within companywide decision-making.

The chair will have an obligation to report deliberation results to the CEO, and major matters will have to be reported to the board. Accordingly, companies must not only prepare for CISO position adjustments but also establish committee composition and operation, as well as management reporting procedures.

The effectiveness of this system will be judged based on whether discussions are actually linked to budget and staffing allocation, and whether they are linked to improvement measures. Companies need to prepare so that related discussions lead to organizational operations and follow-up actions.

At the same time, enhanced certification will be newly introduced for ISMS certification. The enhanced certification will apply to major information and communications service providers, such as telecom companies, and integrated information and communications facility operators among those required to obtain ISMS certification whose sales in the previous year were more than KRW 1 trillion, as well as information and communications service providers and others among those required to obtain ISMS certification whose sales in the previous year were more than KRW 3 trillion. It will also include businesses that were investigated by a public-private joint investigation team within the past 3 years and businesses that were subject to a penalty surcharge within the past 3 years, and the enhanced certification framework means that investigative and penalty histories in addition to sales thresholds affect whether the standard applies.

Accordingly, the impact of a cyber intrusion incident does not end with handling the incident and sanctions. The relevant business must prepare for the strengthened review process in the subsequent certification procedure, and it also needs to manage the link between post-incident improvement measures and the next certification review.

Certification reviews will be strengthened as the review method changes. Document reviews and on-site reviews, which had previously been optional separately, will be conducted in parallel, and technical reviews such as vulnerability checks will also be carried out for entities subject to enhanced certification and companies that have experienced incidents.

Companies will be checked for management system-related documents and the actual security status of their systems. Accordingly, the certification review will be conducted in a way that includes on-site and technical checks in addition to document verification.

For incident response, the basis for government investigations will be expanded. If circumstances indicating a cyber intrusion incident are identified, the government may launch an ex officio investigation, and the Cyber Intrusion Incident Investigation Deliberation Committee under the Ministry of Science and ICT will be operated. The committee will deliberate on matters such as the need for a prompt investigation.

Economic sanctions are divided into penalty surcharges and enforcement fines. A penalty surcharge will be imposed on businesses that repeatedly cause cyber intrusion incidents through intent or gross negligence, and the standard for the surcharge is within 3% of related sales revenue depending on the severity of the incident. However, this is not a sanction that is applied uniformly to all companies simply because a cyber intrusion incident has occurred.

The government will separately pursue responsibility for repeated incidents and responsibility for non-cooperation with investigations and corrective action, and it will impose enforcement fines on businesses that fail to comply with government corrective orders or requests to submit materials. The standard for the fine is 0.02% of the average daily sales revenue for each day of non-compliance. Accordingly, costs will arise in proportion to the period of non-compliance.

Accordingly, companies must conduct root-cause analysis and restore services while also managing schedules for responding to government requests to submit materials and for complying with corrective orders. As the need to respond to strengthened certification reviews and the need to respond to sanctions after incidents both grow, the importance of cooperation among technical, legal, and management departments during incident response is also increasing.

The areas requiring adjustment under the institutional changes are the authority of security organizations and actual operations. Merely appointing a CISO as an executive cannot guarantee preventive effects, and merely establishing a committee cannot guarantee preventive effects either. In addition, if the budget needed to improve vulnerabilities is not secured, or if staffing is not secured, preventive effects are hard to expect. Ultimately, management reporting needs to be linked to concrete investment and concrete action.

Deputy Prime Minister and Minister of Science and ICT Bae Kyung-hoon said the implementation of the Network Act and enforcement decree has established an institutional foundation for strengthening companies’ security awareness and accountability. He added that he hopes companies will see security not as a simple cost but as an essential element of management, said he expects active security investment from companies, and said the government plans to actively support the successful establishment of the system.

Source: IT DAILY · Lee Jae-young
Original: https://www.itdaily.kr/news/articleView.html?idxno=241950

References

This article was produced with the help of an automated content generation algorithm.


Source: IT DAILY

View original

This article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.