Korean Law in English
Laws › Act on Promotion of Information and Communications Network Utilization and Information Protection › CHAPTER VI SECURING OF STABILITY OF INFORMATION AND COMMUNICATIONS NETWORKS

Act on Promotion of Information and Communications Network Utilization and Information Protection — Article 47 (Certification of information security management systems)

정보통신망 이용촉진 및 정보보호 등에 관한 법률 제47조

This English translation is based on the Korean text effective 2025-10-01. The Korean law has since been amended (current version effective 2026-10-02) — check the Korean original.

(1) With respect to a person who establishes and operates a comprehensive management system, including administrative, technical, and physical protective measures, for ensuring stability and reliability of an information and communications network (hereinafter referred to as "information security management system"), the Minister of Science and ICT may certify as to whether such person meets the standards under paragraph (4). <Amended on Feb. 17, 2012; Mar. 23, 2013; Dec. 1, 2015; Jul. 26, 2017>

(2) A telecommunications business operator under subparagraph 8 of Article 2 of the Telecommunications Business Act, or any of the following persons who provides or intermediates the provision of information by using telecommunications services of any telecommunications business operator, shall receive the certification under paragraph (1): <Added on Feb. 17, 2012; Dec. 1, 2015; Dec. 24, 2018; Jun. 9, 2020; Jan. 23, 2024>

1. A person who renders information and communications network services, as prescribed by Presidential Decree, as a person registered pursuant to Article 6 (1) of the Telecommunications Business Act (hereinafter referred to as a "major provider of information and communications services");

2. A integrated information and communication facility operator;

3. A person meeting the standards prescribed by Presidential Decree, whose sales, tax revenue, or any similar for the previous year is at least 150 billion won, whose sales in the information and communications service sector for the previous year is at least 10 billion won, or whose average daily users for the previous year is at least 1 million.

(3) Where a person required to be certified in accordance with paragraph (2) is certified for conformity with international standards for information protection or takes measures for information protection, as prescribed by Decree of the Ministry of Science and ICT, the Minister of Science and ICT may omit part of certification examination under paragraph (1). In such cases, the detailed scope of omitted certification examination shall be determined and publicly notified by the Minister of Science and ICT. <Added on Dec. 1, 2015; Jul. 26, 2017>

(4) For the purpose of certification of an information security management system under paragraph (1), the Minister of Science and ICT may determine and publicly notify certification standards, etc. including countermeasures for administrative, technical, and physical protection and other necessary matters. <Amended on Feb. 17, 2012; Mar. 23. 2013; Dec. 1, 2015; Jul. 26, 2017>

(5) The period of validity of the certification of an information security management system under paragraph (1) shall be 3 years; provided, upon receipt of any information security management gradein accordance with Article 47-5 (1), the certification under paragraph (1) shall be deemed effective during the period of validity of such rating. <Added on Feb. 17, 2012; Dec. 1, 2015>

(6) The Minister of Science and ICT may have the Korea Internet and Security Agency or any institution designated by the Minister of Science and ICT (hereinafter referred to as "certification body for information security management systems") perform the following affairs related to the certification under paragraphs (1) and (2): <Added on Feb. 17, 2012; Mar. 23. 2013; Dec. 1, 2015; Jul. 26, 2017>

1. Examination to verify whether the information security management system established by an applicant for certification meets the certification standards under paragraph (4) (hereinafter referred to as "examination for certification");

2. Review on the results of examination for certification;

3. Issuance and management of written certifications;

4. Follow-up management of granted certifications;

5. Fosterage and qualification management of the certification examiners of information security management systems;

6. Other affairs regarding the certification of information security management systems.

(7) If necessary for the efficient conduct of affairs related to certification, the Minister of Science and ICT may designate an institution that performs affairs related to examination for certification (hereinafter referred to as "examination institution for information security management systems"). <Added on Dec. 1, 2015; Jul. 26, 2017>

(8) The Korea Internet and Security Agency, a certification body for information security management systems, and an examination institution for information security management systems shall, in order to enhance the efficiency of information security management systems, perform follow-up management at least once a year and notify the Minister of Science and ICT of the results thereof. <Added on Feb. 17, 2012; Mar. 23. 2013; Dec. 1, 2015; Jul. 26, 2017>

(9) A person who has received the certification of an information security management system in accordance with paragraphs (1) and (2) may indicate or publicize the content of the certification, as prescribed by Presidential Decree. <Amended on Feb. 17, 2012; Dec. 1, 2015>

(10) The Minister of Science and ICT may revoke the certification where any of the following grounds is found; provided, in cases falling under subparagraph 1, the Minister of Science and ICT shall revoke the certification: <Added on Feb. 17, 2012; Mar. 23. 2013; Dec. 1, 2015; Jul. 26, 2017>

1. Having received the certification of an information security management system by fraud or other improper means;

2. Falling short of the certification standards under paragraph (4);

3. Refusing or obstructing the follow-up management under paragraph (8).

(11) Methods and procedures for, and scope and fees of, certification under paragraphs (1) and (2), methods and procedures for follow-up management under paragraph (8), methods and procedures for revoking certification under paragraph (10), and other necessary matters shall be prescribed by Presidential Decree. <Amended on Feb. 17, 2012; Dec. 1, 2015>

(12) Standards and procedures for, and period of validity of, the designation of a certification body for information security management systems and an examination institution for information security management systems, and other necessary matters shall be prescribed by Presidential Decree. <Amended on Feb. 17, 2012; Dec. 1, 2015>[This Article Wholly Amended on Jun. 13, 2008]

‹ Article 46-3All articlesArticle 47-2 ›

Korean original (law.go.kr) · Get articles as JSON via API

For AI agents and developers — get this article as JSON, with the English and current Korean effective dates and an outdated-translation flag, from the korea-law API or as an MCP tool: https://mcp.apify.com?tools=kr-data/korea-law