Companies that repeatedly cause cyber incidents through intent or gross negligence will face administrative fines of up to 3 percent of related revenue. The status of a company’s chief information security officer (CISO) will be raised to executive level, and the establishment of an information security committee will become mandatory.
The Ministry of Science and ICT said on Tuesday that the revised Act on Promotion of Information and Communications Network Utilization and Information Protection and its enforcement decree, which strengthen the information security system from prevention to post-incident response and sanctions, will take effect on Oct. 1.
The measure is intended to support a pan-government information security package prepared after a series of major breaches last year. It focuses on strengthening corporate security responsibility and expanding the government’s proactive investigative authority and financial sanctions on companies where incidents occur.
The government will first strengthen corporate information security governance. Mid-sized companies and others must appoint an executive, rather than an existing employee, as CISO. However, small and medium-sized companies can continue to designate the head of an information security-related department. Companies newly required to appoint an executive as CISO will be given a six-month grace period.
Companies required to report their CISO must also establish and operate an information security committee. The CISO will serve as chair, and the heads of major departments including IT development, personal data protection, human resources and finance will participate to deliberate key matters such as securing information security budgets and staffing. The results will be reported to the chief executive officer, and key matters will also be reported to the board of directors.
A strengthened certification system will be newly introduced for the Information Security Management System (ISMS). It applies to major information and communications service providers such as telecom operators with 1 trillion won or more in annual revenue in the previous year, operators of clustered information and communications facilities, and information and communications service providers with 3 trillion won or more in revenue. It also includes businesses that have been investigated by a public-private joint investigation team or have received administrative fines within the past three years.
Certification screening will be tightened by combining document review and on-site inspections, instead of the existing optional approach. Companies subject to strengthened certification or those where a breach occurs will also undergo technical reviews such as vulnerability checks. The government will also increase its authority to investigate incidents. If indications of a breach are secured, the government can launch an ex officio investigation, and a Cyber Incident Investigation Review Committee will be operated to deliberate on such investigations.
Businesses that fail to comply with corrective orders or requests for 자료 submissions will face enforcement penalties equivalent to 0.02 percent of average daily sales for each day of non-compliance. Information and communications service providers that have two or more incidents within five years due to intent or gross negligence may be fined up to 3 percent of related revenue, taking into account factors including the severity of the incident.
Deputy Prime Minister Bae Kyung-hoon (배경훈), who also serves as science minister, said, "I hope companies recognise security not as a simple cost but as an essential element of management and translate that into active investment." He said, "The government will also actively support the system taking root to create a digital environment that the public can use with confidence."