(1) Any of the following persons shall take protective measures to secure the reliability of the information and ensure the stability of the information and communications networks used to provide information and communications services: <Amended on Jun. 9, 2020>
1. A provider of information and communications services;
2. A person who manufactures or imports devices, equipment, and facilities prescribed by Presidential Decree, among devices, equipment, and facilities which can transmit or receive information by being connected to an information and communications network (hereinafter referred to as "devices and the like connected to an information and communications network").
(2) The Minister of Science and ICT may determine and give public notice of guidelines for protective measures for information (hereinafter referred to as "information protection guidelines"), specifying details of the protective measures under paragraph (1) and may recommend any of the persons falling under paragraph (1) to observe the guidelines. <Amended on Feb. 17, 2012; Mar. 23, 2013; Jul. 26, 2017; Jun. 9, 2020>
(3) The information protection guidelines shall contain descriptions of the following: <Amended on Mar. 22, 2016; Jun. 9, 2020>
1. Technical and physical protective measures, including installation and operation of an information security system, to prevent or counteract access to or invasion upon an information and communications network by a person with no due authorization;
2. Technical protective measures for preventing unlawful leakage, forgery, alteration, or deletion of information;
3. Technical and physical protective measures for securing the state of enabling continuous use of information and communications networks;
4. Administrative protective measures for stabilization of information and communications networks and protection of information, including securing human resources, organization, and expenses and establishing related plans;
5. Technical protective measures for information security of devices and the like connected to an information and communications network.
(4) The Minister of Science and ICT may request the heads of relevant central administrative agencies to reflect the content of the information security guidelines in standards for testing, inspection, certification, etc. related to devices and the like connected to information and communications networks with regard to the substantive areas under their jurisdictions. <Added on Jun. 9, 2020>[This Article Wholly Amended on Jun. 13, 2008]