Policy

Government to Toughen Discipline for Public-Sector Data Leaks, Hold Agency Heads Accountable for Serious Incidents

IT DAILY ·

Image generated by AI

✦ AI Summary

As personal data leaks and hacking incidents continue to occur in the public sector, the government is pushing to expand disciplinary responsibility from frontline workers to agency heads and other managers. The Ministry of Personnel Management plans to revise the Rules on Disciplinary Measures for State Public Officials within this year so that managers can also be held accountable in the event of data leaks, while the minimum level of discipline will be raised from a written warning to a pay cut. The government is also considering including violations of basic rules, such as failing to change an initial password, in disciplinary action, along with expanding the National Intelligence Service's cyberthreat status assessment and introducing incentives for information security personnel.

As personal data leaks continue to pile up in the public sector, the government is pushing to strengthen disciplinary measures by expanding the scope of responsibility from frontline workers to managers. Under the plan, if a serious incident occurs, managers including agency heads will also face disciplinary accountability, and when an accident happens, managers as well as frontline workers will be subject to censure. The government will also pursue standards so that violations of basic rules, such as using an initial password without changing it, can lead to discipline.

The Ministry of the Interior and Safety, the National Intelligence Service, the Ministry of Personnel Management and the Personal Information Protection Commission announced measures to strengthen cybersecurity accountability in the public sector on the 1st. The plan reflects the reality that public institutions are exposed to rising cyberattacks.

The background is a series of hacks and information leaks at public institutions, such as the Onnara system and the National Diplomatic Academy's online education system. The Onnara system is a government work system for civil servants. Last year, signs of hacking were confirmed in connection with the Onnara system over a 3-year period from September 2022 to July 2025.

This year, the National Diplomatic Academy's online education system was hacked from April 2025 to February of this year. The National Diplomatic Academy is an institution under the Ministry of Foreign Affairs. The hack leaked information on diplomats.

At a briefing held that day at the Government Seoul Complex in Jongno-gu, Seoul, Hwang Gyu-cheol, head of the Artificial Intelligence Government Office at the Ministry of the Interior and Safety, said accidents that could have been prevented simply by following basic rules are recurring in the public sector. He explained that the cause of these repeated incidents is not simple mistakes, but a lack of security awareness.

The government has decided to tighten disciplinary standards to raise cybersecurity awareness in the public sector. Accordingly, the Ministry of Personnel Management plans to revise the Rules on Disciplinary Measures for State Public Officials within this year so that managers, including agency heads, can also be held responsible when data leaks occur.

The measures subject to tougher discipline include leaks of classified information, personal data leaks, and hacks resulting from lax security management. The minimum level of disciplinary action will also be raised from a written warning to a pay cut.

The government also decided to establish new handling standards so that violations of basic rules can lead to discipline. For example, if it is confirmed that someone used an initial password without changing it, that person will be subject to disciplinary action.

The government's tougher discipline measures will primarily apply to public officials at Grade 1 and below in terms of actual disciplinary coverage. Political appointees, including ministers and vice ministers, are excluded from disciplinary action under the State Public Officials Act. Kim Jae-seon, head of the Personnel Management Division at the Ministry of Personnel Management, said measures concerning political appointees could instead be handled through the president's personnel authority.

The government is also pushing to strengthen agency evaluations. The scope of the National Intelligence Service's "Cybersecurity Status Assessment" will expand from 153 organizations this year to around 2,000 by 2028. The assessment will introduce new indicators that deduct points for information leak incidents and reflect whether swift action was taken.

Along with tougher discipline, the government is also pursuing incentives for information security personnel. This is because security work carries a heavy burden of responsibility when incidents occur, makes it difficult to prove performance, and could become an undesirable assignment as a result.

The incentive measures under review include creating a security-duty allowance, granting extra points in performance evaluations, and including information security work among the criteria for designation as an important post. Kim Jae-seon, head of the Personnel Management Division at the Ministry of Personnel Management, said that technical staff such as IT officials currently receive a technical information allowance, and that the ministry is considering establishing a separate allowance for personnel in charge of information security work. He also said it is considering a plan to grant extra points in the twice-yearly work performance evaluation.

At the briefing that day, along with other issues, the personal data leak incident at the "1365 Volunteer Portal," run by the Ministry of the Interior and Safety, was also mentioned. The 1365 Volunteer Portal was hit by an external attack on May 20, and the names, dates of birth, and mobile phone numbers of 8,765 users were reportedly leaked.

Ko Nak-jun, commissioner at the Personal Information Protection Commission's Prevention and Coordination Deliberation Division, said an investigation into the incident is under way. He explained that, because the case is still under investigation, it is difficult to disclose specific details.

Source: IT DAILY · Kim Ho-jun
Original: https://www.itdaily.kr/news/articleView.html?idxno=241973

References

This article was produced with the help of an automated content generation algorithm.


Source: IT DAILY

View original

This article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.