AI & Enterprise
Executive-rank designation for CISOs to become mandatory, standards still unclear
South Korea’s cabinet has approved revisions to the Network Act requiring companies to appoint a chief information security officer (CISO) at executive level, with detailed applicability criteria to be set by enforcement decree. The law is expected to be promulgated as early as next week and take effect six months later, with some provisions delayed by a year. Data cited by KISA show many firms, especially mid-sized ones, still lack executive-level CISOs.