South Korea can now launch onsite investigations based solely on signs of hacking, even if a company does not report an incident, as cyber intrusions including in the financial sector continue.
Vice Prime Minister and Minister of Science and ICT Baek Kyung-hoon (배경훈) said at an audit of the ministry by the National Assembly Science, ICT, Broadcasting and Communications Committee on Monday that revisions to the Information and Communications Network Act took effect on Oct. 1. He said the change makes it possible to conduct onsite investigations based only on indications of hacking, without a company report.
Baek said cyber intrusions are escalating and South Korea is heavily exposed to attacks because of its high use of the internet and smart devices.
Until now, the government’s incident investigations have largely been carried out after companies report an incident. Critics have said this limits the speed of identifying causes and responding if an operator does not report or delays reporting.
The revised Act on Promotion of Information and Communications Network Utilization and Information Protection, which took effect on Oct. 1, established an Intrusion Incident Investigation Deliberation Committee to strengthen the investigation system. If an investigation is deemed necessary to determine whether an intrusion has occurred, the committee can deliberate to set the scope and method of the probe.
The government previously said it would expand investigative authority so it can start probes without a company report if it secures indications of hacking, after a series of large-scale hacking incidents in areas closely tied to daily life such as telecommunications and finance. With the revised law and its enforcement decree taking effect this month, the related institutional basis has been 마련됐다.
The revised law also includes provisions to impose penalties on information and communications service providers where intrusion incidents repeatedly occur, and to require user notification when certain incidents occur. It also strengthened regulations related to the authority of chief information security officers (CISO) and the information security management system (ISMS).
Baek said the system has not yet shown effectiveness because it has not been in place for long. He added he expects the changes to prove effective going forward.
He added the ministry will take the lead in standardising incident management and response manuals and in sharing information among relevant companies and ministries.
At the audit, lawmakers also raised calls to further strengthen the government’s cyber intrusion response system.
Suh Cheon-ho (서천호), a lawmaker from the People Power Party, said intrusion incidents are occurring across government agencies, public institutions, research bodies, telecommunications companies and the financial sector. He said the Ministry of Science and ICT should be keenly aware of its responsibility because it oversees hacking response.
Baek said the government increased next year’s information security-related budget by 44 percent to 523.2 billion won from 363.4 billion won this year, and will strengthen cyber intrusion response capabilities.