HBL
HANBYOL LAW LLC

News & Insights

Back to List
뉴스2015년 10월 6일

[Security News] What are the main issues with the two recently enacted data protection laws?

Council of Chief Information Security Officers, CISO Forum held in September 2015
Introduction of key contents and issues of the Information Security Industry Promotion Act-Cloud Computing Development Act


[Security News Minseah] On September 22, 2015, the September CISO Forum 2015 was held at the Intercontinental Seoul COEX in Seoul, South Korea, with the participation of information security chief information officers and security practitioners.


▲The
 September 2015 CISO Forum, hosted by the Council of Chief Information Security Officers, was held on September 22 at the Grand InterContinental Seoul COEX.

In his opening remarks, Lee Hong-seop, Chairman of the Council of Chief Information Security Officers, noted that cybercrime has emerged as a safety topic through the 'International Indicators and Big Data Analysis for the Past Six Months' published by an organization. Cyber risks such as information leakage were cited as a safety issue that will emerge in the future.


"There's a lot of talk about cybersecurity, cybersecurity, but a lot of people don't know where to start," Lee said. Corporate CISOs should take the center stage and prepare proper cybersecurity measures."


Later, Jeong Geun-geun, Information Security Policy Officer at the Ministry of Science, ICT and Future Planning, said, "We will work hard to think of ways to make the public think of cybersecurity as an essential task for safety, and to encourage companies to invest more in cybersecurity.


The topic was then presented by Kim Min-seop, Senior Research Fellow at the Legal Team of the Policy Research Unit of the Korea Internet & Security Agency, and Jeong Jae-wan, Attorney at Hanbyul Law Firm.


Information Protection Industry Promotion Act Main Contents and Expected Effects

Minseop Kim, Senior Research Fellow at the Korea Internet & Security Agency, presented the main contents of the Information Protection Industry Promotion Act and its subordinate bills under the topic of 'Major Contents and Expected Effects of the Act'. The Information Protection Industry Promotion Act, which was proposed in July last year, will be fully implemented on December 23 after enacting subordinate laws.


The main contents of the Information Protection Industry Promotion Act and subordinate bills are as follows. The first is the establishment of a plan for the promotion of the information protection industry, which covers technology development, training of specialized personnel, entry into convergence new markets, and overseas expansion. The plan is planned to be established every five years, but since the information protection industry is a rapidly developing field, the subordinate decree gives flexibility to revise it on an as-needed basis.

 

The second is the provision of purchasing demand information. The public sector collects purchase demand information on information protection and provides it to information protection companies, which in turn provides the collected information to information protection companies that receive orders. The Ministry of Future Affairs provides purchase demand information twice a year, and a related system has been established.


Next, we come to the part about approving business subcontracting. In the case of information protection system construction contracts, subcontracting is not only permitted, but is required by law to be approved in writing by the ordering public institution.


Fourth is paying fair value for information security products and services. It's about ensuring that the organization receiving the order is getting what it's paying for, and that it's not being paid for the product or service. In fact, it will be investigated through public-private monitoring to see if the proper price is being paid, and if the proper price is not being paid, the results will be announced.  


Fifth, conduct an information security readiness assessment. The subordinate law will provide details on how to conduct an information security readiness assessment that evaluates information security preparation efforts, such as security investment and human resource management systems, and assigns a rating to companies.


Sixth is the information protection disclosure system. The information security disclosure system is a voluntary system for companies to disclose their information security industry investment and certification status. It is not a regulatory requirement, but it is reported that incentives such as reducing the ISMS certification fee by a certain amount will be added for companies that disclose.  


The bill also includes a proposal to create a system for training and managing professional human resources by creating a professional human resources management system.  


The eighth provision is the support for information security performance evaluation, which means that when an information security organization applies for an evaluation of an information security product, the performance evaluation organization will evaluate it and notify it of its approval or disapproval. Information security performance assessment is different from CC certification in that it focuses on specific indicators, Kim explained.


Along with this, provisions such as 'designation of excellent information protection technologies and enterprises' and 'support for information protection enterprises' are the main outlines of the bill, and detailed implementation policies for these provisions will be stipulated in the Enforcement Decree and Enforcement Rules.


Cloud Computing Development Act Security Issues

   ▲법무법인 한별 정재완 변호사

Hanbyul Jung gave a presentation on 'Security Issues of the Cloud Computing Development Act', which will be implemented on September 28th.

Cloud computing technology has the advantage of reducing costs by eliminating the need to purchase, maintain, and manage hardware and software because IT resources are rented, and increasing productivity by enabling employees to work anywhere and anytime with an internet connection. However, there is a very serious problem that if the network or cloud service stops, the related work stops, so Jung said that the information protection aspect is likely to be strengthened in the future Cloud Computing Development Act.


Lawyer Yi explained the main contents of the Cloud Computing Development Act and what security personnel should keep in mind. First, he raised the need to resolve conflicts and overlaps between the current Cloud Computing Development Act and other laws.


In addition, since cloud computing service agreements are often concluded online, rather than face-to-face, they are often in the form of electronic terms and conditions, which should be easily recognizable by the user, and the service agreement should specify contractual requirements, including obligations related to security and privacy, according to Jung.   


According to Chung, cloud computing services are subject to the Personal Information Protection Act and the Information and Communications Network Act, so safety measures such as governance, location of data, insider access, and protection of the virtual network environment must be taken in accordance with relevant laws.  


If an infringement occurs and user information is leaked or the service is interrupted, the user shall immediately notify the Minister of Science, ICT and Future Planning and notify the user by telephone, mobile phone, mail, e-mail, text message, posting on the Internet homepage, etc.


Cloud computing services are subject to a monthly cumulative 3.The cloud computing service requires continuous performance evaluation, such as ensuring that the time of failure during the service is kept within a cumulative 3. 6 hours per month, and the management and supervision responsibilities of the outsourcer may be problematic due to the entrustment of personal information. In addition, legal issues related to the transfer of personal information overseas have recently emerged as an issue, and users may request to be informed of the name of the country where their information is stored.


Finally, Mr. Chung spoke about the direction of legislative improvement of the Cloud Computing Development Act. "If you look at the Cloud Computing Development Act, it is mostly for promotion, but considering that the industry is in its infancy, it may need to be revised in the future to protect users. In addition, since cloud computing is an aggregation of information, the damage is very serious if an infringement occurs, but the current law lacks measures to prevent infringement, so it is necessary to enact related notices such as information protection standards."


He added,  To ensure the availability of cloud computing, measures should be taken to ensure service reliability, such as introducing a performance guarantee insurance system.

[Reporter Minsea Min (boan5@boannews.com)]

Lawyers:

HBL
HANBYOL LAW LLC

HANBYOL LAW LLC protects our clients' rights and provides the best legal services.

Location

6F & 7F, Samwon Tower, 124 Teheran-ro, Gangnam-gu, Seoul (Yeoksam-dong)

TEL: 02-6255-7777 | FAX: 02-6255-7996~9

Email: hanbl@hanbl.co.kr

© 2026 HANBYOL LAW LLC. All rights reserved.