skip to main content skip to main menu

Government Legislation

  • [IT & IPR] Enforcement Decree of the Act on Promotion of Information and Communications Network Utilization and Information Protection, Etc.
    • Competent Ministry : Ministry of Science and ICT
    • Advance Publication of Legislation : 2026-07-09
    • Opinion Submission Deadline : 2026-08-18

[Background of Promotion] 

o As security breaches of large-scale information and communications service providers have occurred consecutively, the need has emerged to clarify the responsibilities of the Chief Information Security Officer (CISO), who oversees corporate information protection, and to practicalize their duties. 

o Article 45-3, Paragraph 4, Item 1, Sub-item (g) of the Act delegates "matters prescribed by Presidential Decree" among the duties of the CISO to the Enforcement Decree, making it necessary to clearly stipulate the specific scope in accordance with the intent of the delegation.


[Regulatory Content] 

o In accordance with the delegation under Article 45-3, Paragraph 4, Item 1, Sub-item (g) of the Act, the matters to be performed by the CISO are specified as follows (establishment of Article 36-7, Paragraph 7 of the Enforcement Decree):

- Security review and approval when introducing or modifying information systems or information and communications services
- Regular security level inspection and supervision of cloud computing service providers and those entrusted with or acting on behalf of the construction, operation, and management of information and communications systems, or information processing tasks
Regulatory effect assessment
Legislative proposal (draft)
  • (과학기술정보통신부 공고 제2026-754호) 정보통신망 이용촉진 및 정보보호 등에 관한 법률 시행령 일부개정령안 입법예고.hwpx
    [Legislative proposal (draft) download]