(1) A provider of information and communications services shall designate an executive officer or employee meeting the standards prescribed by Presidential Decree as a chief information security officer and shall file a report thereon to the Minister of Science and ICT, in order to ensure the security of information and communications systems, etc. and safe management of information; provided, a provider of information and communications services whose total assets, turnover, and the like meet the criteria prescribed by Presidential Decree need not file a report on such chief information security officer. <Amended on May 28, 2014; Jul. 26, 2017; Jun. 12, 2018; Jun. 8, 2021>
(2) Methods and procedures for reporting under paragraph (1) and other matters shall be prescribed by Presidential Decree. <Added on May 28, 2014>
(3) No chief information security officer designated and reported under the main clause of paragraph (1) (limited to where a provider of information and communications services whose total assets, turnover, and the like meet the criteria prescribed by Presidential Decree) may hold another office concurrently, other than perform duties referred to in paragraph (4). <Added on Jun. 12, 2018>
(4) A chief information security officer shall perform the following duties: <Amended on Jun. 8 2021>
1. The chief information security officer shall be responsible for the following duties:(a) To formulate, implement, and improve information protection plans;(b) To conduct regular audit and improve the actual conditions and practices of information protection;(c) To identify and evaluate risks relating to information protection and develop countermeasures for information protection;(d) To formulate and implement plans for information protection education and simulation training;
2. The chief information security officer may hold another office concurrently to perform the following:(a) Duties of providing information security disclosure under Article 13 of the Act on the Promotion of Information Security Industry;(b) Duties of chief information security officers under Article 5 (5) of the Act on the Protection of Information and Communications Infrastructure;(c) Duties of chief information security officers under Article 21-2 (4) of the Electronic Financial Transactions Act;(d) Duties of privacy officers under Article 31 (2) of the Personal Information Protection Act;(e) Taking other measure necessary for information protection in accordance with this Act or any other relevant statute or regulation.
(5) A provider of information and communications services may establish and operate a council of chief information security officers comprised of chief information security officers prescribed in paragraph (1) in order to jointly prevent and respond to a cyber security incident, share necessary information, and implement other joint programs prescribed by Presidential Decree. <Amended on May 28, 2014; Jun. 12, 2018>
(6) The Government may fully or partially provide support to the Council of Information Security Officers under paragraph (5) for expenses incurred in conducting its activities. <Amended on May 28, 2014; Jun. 22, 2015; Jun. 12, 2018>
(7) Necessary matters regarding qualifications, etc. of chief information security officers shall be prescribed by Presidential Decree. <Added on Jun. 12, 2018>[This Article Added on Feb. 17, 2012]