[Background of Promotion]
o As security breaches of large-scale information and communications service providers have occurred consecutively, the need has emerged to clarify the responsibilities of the Chief Information Security Officer (CISO), who oversees corporate information protection, and to practicalize their duties.
o Article 45-3, Paragraph 4, Item 1, Sub-item (g) of the Act delegates "matters prescribed by Presidential Decree" among the duties of the CISO to the Enforcement Decree, making it necessary to clearly stipulate the specific scope in accordance with the intent of the delegation.
[Regulatory Content]
o In accordance with the delegation under Article 45-3, Paragraph 4, Item 1, Sub-item (g) of the Act, the matters to be performed by the CISO are specified as follows (establishment of Article 36-7, Paragraph 7 of the Enforcement Decree):
- Security review and approval when introducing or modifying information systems or information and communications services
- Regular security level inspection and supervision of cloud computing service providers and those entrusted with or acting on behalf of the construction, operation, and management of information and communications systems, or information processing tasks