Telecom

[Weekly Signal] Telecommunications CISOs to Appear at Science, ICT, Broadcasting and Communications Committee Audit of Government…Security Systems Under Intensive Review

IT DAILY ·

[Photo: Korea Copyright Commission's Sharing Plaza]

✦ Resumen de IA

On October 6, the CISOs of the three major mobile carriers are among those set to appear at the National Assembly's Science, ICT, Broadcasting and Communications Committee audit.

The committee plans to review the security systems, responses to intrusion incidents, security investment and staffing operations, and user protection measures of SK Telecom, KT, and LG Uplus.

The Broadcasting and Media Communications Commission unveiled its first-year vision, and TTA launched consulting services to support licensing for AI- and SW-based digital medical devices.

This week in the telecom industry, an audit by the National Assembly's Science, ICT, Broadcasting and Communications Committee (SICBC) is scheduled for October 6. The CISOs of the three major mobile carriers are among those required to appear at the audit.

Those set to appear are Lee Jong-hyeon, head of the integrated security center at SK Telecom; Lee Sang-woon, head of KT's information security office; and Hong Kwan-hee, head of LG Uplus's information security center. The SICBC plans to examine the telecom companies' security systems and their responses to intrusion incidents.

The focus of this review is on security investment by the three mobile carriers. The overall response by the three carriers to security issues is expected to come under scrutiny during the audit.

At the same time, the Broadcasting and Media Communications Commission unveiled its first-year vision just one year after its launch. The commission also strengthened a user-participation reporting system. The Telecommunications Technology Association (TTA) has launched consulting services to support licensing for AI- and SW-based digital medical devices.

The National Assembly's Science, ICT, Broadcasting and Communications Committee plans to review the three carriers' protective measures after security incidents, their information security systems, investment and staffing operations, and measures to protect users. The committee is planning to question SKT on the 2025 cyber intrusion incident, including protection of USIM information, improvements to the information security management system, compensation for user damage and measures to prevent recurrences, and the status of information security investment implementation.

The committee is also planning to question KT and LG Uplus. The questions will cover responses to security incidents, information security systems after the reorganization of security teams, the status of security investment and staffing operations, prevention of telecommunications network intrusions, and institutional improvements to protect users.

Among them, SK Telecom was sanctioned last year by the Personal Information Protection Commission (PIPC) in connection with a cyber intrusion incident. The sanctions included a KRW 134.791 billion fine and a KRW 9.6 million penalty. SK Telecom has challenged the PIPC's sanctions and filed a lawsuit with the Seoul Administrative Court in January this year seeking to cancel the fine, and the first-trial proceedings are now under way.

KT was also fined KRW 53.979 billion last year over a personal information breach incident. The PIPC also took additional action to file a complaint against KT, citing failure to report malware infection in March 2024, deletion of some logs from the affected server, concealment of the incident, submission of false materials during the investigation, and obstruction of the investigation.

LG Uplus was found to have reinstalled or discarded the OS of a server related to an investigation into a personal information leak in August last year, and this was done before the PIPC began its investigation. The commission determined that the measure made it difficult to confirm the exact circumstances of the leak and whether there had been any additional leakage.

The PIPC viewed this as an act of destroying evidence and requested an investigation by law enforcement authorities.

On the 30th, the Broadcasting and Media Communications Commission held its 39th plenary meeting of 2026 and approved the 'First-Year Vision and Key Policies (Draft),' which includes four major goals and 12 policy tasks. As its direction for implementation, the commission emphasized strengthening consumer rights in the telecom sector.

Since last June, the commission has been operating a 'user-participatory voluntary reporting system.' The system covers damage cases requiring evidence, such as advertising and other subsidy payments and unfair subscriptions to additional services, and users can file reports directly.

To reduce abuse of the reporting system and prioritize relief for actual victims, the commission also proposed providing processing status through the reporting system and limiting the number of reports per year. This is intended to give priority to reports from actual victims.

The commission plans to use accumulated reporting data to improve the system and also to use it for market inspections. It aims to supplement related response systems through the accumulation and use of reporting data.

In addition, it will expand mediation organizations to help protect the rights and interests of telecom users. It also plans to push ahead with the development of an AI model specialized in telecom disputes.

Meanwhile, with the Digital Medical Products Act taking effect last year, licensing regulations reflecting AI and SW characteristics were introduced. As a result, while some companies are accustomed to hardware-centered regulations, they now need to build a new quality management system centered on AI and SW.

The Telecommunications Technology Association (TTA) supports medical device manufacturers in responding to licensing requirements. On September 29, TTA will launch the 'Medical Device Quality Management System Consulting' service and the 'Digital Medical Device Conformity Verification' service.

TTA is supporting the establishment of a quality management foundation to ease companies' regulatory burdens, and it is operating two forms of support for that purpose.

One is consulting for a medical device quality management system based on the requirements of ISO 13485. The scope of support covers the establishment and improvement of the quality management system across the entire process, from medical device design and development to production and delivery.

The other is conformity verification for digital medical devices based on IEC 62304. IEC 62304 is an international standard related to software life cycle processes for medical devices, and the service is consulting support for preparing the 'digital medical device software conformity verification report' required for digital medical device licensing reviews. Applications for the service can be made through the TTA customer service website.

Source: IT DAILY · Seong Won-young
Original: https://www.itdaily.kr/news/articleView.html?idxno=242001

References

This article was produced with the help of an automated content generation algorithm.


Source: IT DAILY

Ver original

This article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.