▲ Ministry of the Interior and Safety
Disciplinary standards are set to be tightened so that not only working-level employees but also supervisors, including agency heads, will be held accountable in the event of a severe data leakage incident at a public institution.
Violations of basic security rules, such as failing to change initial passwords or leaving security vulnerabilities unaddressed for long periods, will also become clear grounds for disciplinary action.
The government, jointly with related ministries including the Ministry of the Interior and Safety, the National Intelligence Service, the Ministry of Personnel Management, and the Personal Information Protection Commission, announced the "Measures to Strengthen Public Sector Cybersecurity Accountability" containing these details.
This plan was prepared based on the analysis that many of the major security accidents recently occurring in the public sector, such as data leaks at Modu's Startup and ransomware infections at national university hospitals, occurred because basic security rules were not followed.
The government diagnosed that, in particular, even when basic security rules are violated, it rarely leads to actual disciplinary action, and when discipline is applied, it tends to be concentrated on working-level staff rather than managers.
Accordingly, the government decided to explicitly state in regulations such as the "Enforcement Rule of the State Public Officials Disciplinary Decree" that responsibility will be imposed on supervisors when a serious data leakage accident occurs, and to raise disciplinary standards.
Specific handling guidelines applicable to violations of basic information protection rules will be established, such as using initial passwords without changing them or failing to take action on discovered security vulnerabilities for a long time.
The evaluation system for enhancing security capabilities at the agency level will also be overhauled significantly.
The targets of the "Cybersecurity Status Evaluation" supervised by the National Intelligence Service will be expanded from 153 agencies this year to about 2,000 national and public institutions by 2028.
New indicators will also be introduced to the evaluation, such as deducting points when a data leakage accident occurs or examining whether prompt action was taken after an accident.
The government plans to strengthen the security management responsibilities of agencies by reflecting cybersecurity-related evaluation results in central administrative agency specific evaluations and local public enterprise management evaluations.
Incentive plans for personnel in charge will also be reviewed to prevent information protection tasks from becoming avoided duties due to strengthened discipline.
Measures under review include establishing an information protection work allowance, granting bonus points in performance evaluations for personnel in charge, and including information protection tasks in the selection criteria for important duties.
The government will also reinforce cybersecurity personnel in central administrative agencies and metropolitan local governments.
In the mid- to long-term, the government also plans to enhance expertise by establishing dedicated organizations led by private-sector information protection experts.
Plans to stably secure budgets necessary for basic security activities, such as vulnerability checks through mock hacking and replacement of outdated software whose security support has ended, will also be discussed with related ministries.
Hwang Kyu-chul, head of the Artificial Intelligence Government Bureau at the Ministry of the Interior and Safety, said, "The core of this plan is not simply strengthening discipline, but a shift in perception to view security not as a 'hasslesome regulation' but as a 'national mission'."
(Photo provided by the Ministry of the Interior and Safety, Yonhap News)