Cybersecurity 2026

SOUTH KOREA Law and Practice Contributed by: Hwan Kyoung Ko, Tae Joo Kim, Jaeyoung Chang and Ji Hoon Kim, Lee & Ko

user base of at least 1 million in the preceding year, major ISPs and internet data centre (IDC) operators, among others (Article 47 (2) of the Network Act; Arti - cle 49 of its Enforcement Decree). Certification audits are conducted by KISA and accredited certification audit bodies. The certification is valid for three years, and annual post-certification reviews are conducted to confirm continued compliance with the certification standards. Separately, Article 32-2 of PIPA provides for a personal information management system (PIMS) certification. In practice, standalone PIMS certification is not typi - cally pursued; instead, organisations obtain ISMS-P, which combines ISMS and PIMS. ISMS-P is not cur - rently mandatory, and historically it has functioned, for example, as a mitigating factor in the event of PIPA violations. However, if the recently passed amend - ment to PIPA is implemented as enacted, ISMS-P cer - tification is expected to become mandatory for certain large-scale data handlers going forward. Cloud Security Assurance Programme (CSAP) Pursuant to Article 23-2 of the Act on the Develop - ment of Cloud Computing and Protection of Users, a security certification regime for cloud computing services is in operation. State agencies and similar public bodies are required to give priority considera - tion to cloud computing services that have obtained this security certification. KISA serves as the certifi - cation body; however, because public-sector cloud security measures are overseen by the NIS, obtaining CSAP certification requires passing the NIS security suitability assessment. The certification is valid for five years. Certification levels are differentiated based on service type and security level, and CSAP functions in practice as a de facto entry requirement for cloud adoption by public institutions. That said, there is ongoing discussion about easing CSAP requirements. Sector-Specific Security Certification Schemes In the financial sector, under Article 14-2 of the Regulations on the Supervision of Electronic Finan - cial Transactions, a financial institution or electronic financial business operator seeking to use cloud computing services must undergo a safety assess - ment through the “Integrated Support System for CSP Safety Assessments” operated by the FSI.

In the automotive sector, the Ministry of Land, Infra - structure and Transport (MOLIT) enacted the Notifica - tion on the Certification of Automobile Cyber Security Management Systems, etc., adopting the cybersecu - rity management system (CSMS) based on UN ECE R155 regulations. This framework is now formally cod - ified in the Motor Vehicle Management Act, imposing statutory obligations on domestic automobile manu - facturers and importers to obtain CSMS certification and comply with associated security mandates (Arti - cle 30-9 of the Motor Vehicle Management Act). 6. Cybersecurity in Other Regulations 6.1 Cybersecurity and Data Protection Obligation to Implement Security Measures for Personal Information To prevent data breaches – statutorily defined as the loss, theft, leakage, forgery, alteration or damage of personal information – PIPA and the PIPC’s Standards of Security Measures for Personal Information man - date that data handlers implement rigorous technical, organisational and physical security measures. These mandatory measures include: • the management of access rights (Article 5); • strict access controls (Article 6); • the encryption of personal information (Article 7); • the retention and periodic inspection of access logs (Article 8); • the prevention of malware (Article 9); • physical security measures (Article 10); • security measures in preparation for disasters and emergencies (Article 11); and • the secure destruction of personal information (Article 13). Data Breach Notification and Reporting Upon recognising that a data breach has occurred, a data handler must notify the affected data subjects within 72 hours (Article 34 (1) of PIPA). The statutory notice must explicitly include: • the categories of personal information compro - mised; • the timing and circumstances of the breach;

316 CHAMBERS.COM

Powered by