SOUTH KOREA Law and Practice Contributed by: Hwan Kyoung Ko, Tae Joo Kim, Jaeyoung Chang and Ji Hoon Kim, Lee & Ko
vulnerability analyses must be conducted at least once every six months. Absence of a Korean TIBER/CBEST Framework At present, Korea has not introduced a dedicated threat-led penetration testing (TLPT) framework directly corresponding to the EU’s Threat Intelligence- Based Ethical Red Teaming (TIBER) or the UK’s Cyber - security Testing Framework based on Intelligence-Led Ethical Security Testing (CBEST). However, the FSI, as a specialised institution for vulnerability analyses and assessments of electronic financial infrastructure, may incorporate simulated hacking into such analyses and assessments. In practice, there are increasing exam - ples of support for red-team testing of financial insti - tutions, including instances where the FSI’s RED IRIS team, acting as white-hat hackers, attempts server hacking and DDoS attacks against financial institu - tions and evaluates response capabilities. Korea has not yet enacted a comprehensive statute directly equivalent to the EU’s Cyber Resilience Act (CRA) to regulate security issues across the entire life cycle of individual products. Consequently, broad, cross-sector “security-by-design” obligations for ICT products and services remain largely uncodified in formal legislation. Among existing Korean laws, the provision with the broadest applicability to cyber resilience is the “Obli - gation to Implement Information Security Measures”, stipulated in Article 45 of the Network Act. This provi - sion mandates that ICSPs, alongside manufacturers or importers of specific network-connected devices designated by enforcement decree, implement tech - nical and organisational security measures to ensure network stability and the reliability of information uti- lised in service provision (Article 45 (1) of the Network Act). 4. Cyber-Resilience 4.1 Cyber-Resilience Legislation With respect to IoT devices, KISA operates an “IoT Security Certification Service”, but this is a voluntary certification programme rather than a legally man - dated requirement. That said, if a “Framework Act on
Cybersecurity” is enacted in the future, a more com - prehensive cyber-resilience framework – potentially including security requirements for connected devices – may be established, and legislative discussions on this point are ongoing. 4.2 Key Obligations Under Legislation Obligation to Implement Information Security Measures Under the Network Act To guarantee network stability and information reliabil - ity, ICSPs must comply with formal information secu - rity guidelines and implement technical and organi - sational security measures, including strict access controls and the application of encryption technolo - gies (Article 45 (1)). The MSIT holds statutory author - ity to publicly notify the specific parameters of these security measures (Paragraph 2 of the same Article) and may issue corrective orders in the event of non- compliance (Article 64 (4)). IoT Security Certification System Operated by KISA, the IoT Security Certification System is a voluntary framework that evaluates and certifies the security posture of IoT products against established criteria. The certification is divided into two tiers, “Lite” and “Standard”, covering a diverse array of devices ranging from smart home appliances to industrial IoT equipment. Although it lacks binding legal force, the certification offers a significant market advantage; government and public institutions explic - itly grant preferential treatment to certified products during public procurement processes. 5. Security Certification for ICT Products, Services and Processes 5.1 Key Cybersecurity Certification Legislation ISMS Certification ISMS, Korea’s flagship cybersecurity certification scheme, is based on Article 47 of the Network Act. ISMS evaluates whether an organisation’s informa - tion security and data protection management sys - tem is established and operated in accordance with the applicable certification criteria. ISMS certification is mandatory for certain entities, including ICSPs (excluding financial institutions) with an average daily
315 CHAMBERS.COM
Powered by FlippingBook