Korean Law in English
Laws › Act on Promotion of Information and Communications Network Utilization and Information Protection › CHAPTER VI SECURING OF STABILITY OF INFORMATION AND COMMUNICATIONS NETWORKS

Act on Promotion of Information and Communications Network Utilization and Information Protection — Article 48-4 (Analysis of causes of cyber security incidents)

정보통신망 이용촉진 및 정보보호 등에 관한 법률 제48조의4

This English translation is based on the Korean text effective 2025-10-01. The Korean law has since been amended (current version effective 2026-10-02) — check the Korean original.

(1) If a cyber security incident occurs, a person who operates an information and communications network, including a provider of information and communications services, shall analyze the causes of the cyber security incident; respond thereto, based on the results of analysis, for stopping damage from spreading; and take measures necessary to recover from the damage and prevent a recurrence of such cyber security incident. <Amended on Jun. 10, 2022>

(2) If a cyber security incident occurs in an information and communications network operated by a provider of information and communications services, the Minister of Science and ICT may analyze the causes of the cyber security incident and develop countermeasures to stop damage from spreading, to respond to such incident, to recover from damage, and to prevent a recurrence of such incident; and may order the provider of information and communications services (excluding public institutions) to implement necessary measures. <Added on Jun. 10, 2022; Feb. 13, 2024>

(3) The Minister of Science and ICT may inspect whether measures under paragraph (2) have been implemented and order the provider of information and communications services to make a correction for matters requiring supplementation. <Added on Feb. 13, 2024>

(4) Where a serious cyber security incident occurs in an information and communications network operated by a provider of information and communications services, the Minister of Science and ICT may organize a private-public joint investigation team having expertise in the protection of information and analyze the causes of such cyber security incident if necessary for analyzing such causes and developing countermeasures pursuant to paragraph (2). <Amended on Mar. 23, 2013; Jul. 26, 2017; Jun. 10, 2022; Feb. 13, 2024>

(5) If deemed necessary for analyzing the causes of a cyber security incident and developing countermeasures pursuant to paragraph (2), the Minister of Science and ICT may order the relevant provider of information and communications services to preserve relevant data, such as records on access to the relevant information and communications network. <Amended on Mar. 23, 2013; Jul. 26, 2017; Jun. 10, 2022; Feb. 13, 2024>

(6) The Minister of Science and ICT may demand a provider of information and communications services to submit data related to a cyber security incident, if deemed necessary for analyzing the causes of such cyber security incident and developing countermeasures pursuant to paragraph (2); and in the case of a serious cyber security incident, the Minister may require public officials under his or her jurisdiction or a private-public joint investigation team under paragraph (4) to enter the place of business of the relevant person and to investigate the causes of the incident; provided, data corresponding to the communication confirmation data defined in subparagraph 11 of Article 2 of the Protection of Communications Secrets Act shall be submitted in the manner prescribed by that Act. <Amended on Mar. 23, 2013; Jul. 26, 2017; Jun. 10, 2022; Feb. 13, 2024>

(7) The Minister of Science and ICT or the private-public joint investigation team shall not use the information learned through the data submitted and the investigation conducted in accordance with paragraph (6) for any purpose other than the analysis of the causes of the cyber security incident and development of countermeasures and shall destroy it immediately after the analysis of the causes is completed. <Amended on Mar. 23, 2013; Jul. 26, 2017; Jun. 10, 2022; Feb. 13, 2024>

(8) Matters necessary for the methods and procedures for inspection under paragraph (3), the organization and operation of a private-public joint investigation team under paragraph (4), the protection of data submitted pursuant to paragraph (6), the methods and procedures for investigations, etc. shall be prescribed by Presidential Decree. <Amended on Jun. 10, 2022; Feb. 13, 2024>[This Article Wholly Amended on Jun. 13, 2008]

‹ Article 48-3All articlesArticle 48-5 ›

Korean original (law.go.kr) · Get articles as JSON via API

For AI agents and developers — get this article as JSON, with the English and current Korean effective dates and an outdated-translation flag, from the korea-law API or as an MCP tool: https://mcp.apify.com?tools=kr-data/korea-law