Government unveils joint-ministry plan to strengthen cybersecurity accountability in the public sector
Assessment coverage to expand to more than 2,000 institutions by 2028
Personnel incentives planned to prevent staff from shunning information security roles
The government will raise disciplinary standards for managers responsible for security breaches at government agencies and public institutions, while strengthening support for information security personnel to prevent staff from avoiding the work.
The government announced the measures Thursday at Government Complex Seoul, where the Ministry of Interior and Safety, the National Intelligence Service, the Ministry of Personnel Management and the Personal Information Protection Commission jointly unveiled a plan titled "Measures to Strengthen Cybersecurity Accountability in the Public Sector."
Under the plan, the government will establish clear disciplinary guidelines covering basic information security violations — such as failing to change default passwords or leaving known security vulnerabilities unaddressed for extended periods.
Previously, disciplinary action following security incidents had focused mainly on breaches of personal information or classified data, and on deliberate misconduct. No clear guidelines existed for violations of basic security protocols.
The government will also amend the enforcement rules of the Civil Servant Disciplinary Decree to explicitly hold supervisors accountable when serious data breaches occur, and will raise the applicable disciplinary standards.
The plan also calls for improvements to the evaluation framework for institutional security capabilities, along with personnel incentives and expansions of organizational capacity and budgets.
The National Intelligence Service's cybersecurity assessment program, which currently covers 153 institutions, will be expanded to more than 2,000 national and public institutions by 2028.
The assessments will incorporate new indicators — including deductions for data breach incidents and credits for swift incident response. Cybersecurity metrics will also be added to the central government's special performance evaluations and to management assessments of local public enterprises to improve the program's effectiveness.
Alongside this, the government will introduce personnel incentives to prevent staff from shunning information security roles as disciplinary exposure increases. Measures under consideration include creating a dedicated information security allowance, awarding bonus points in performance reviews for information security officers, and designating information security work as a key duty category.
On the organizational and budgetary front, the government plans to reinforce cybersecurity staffing at central administrative agencies and metropolitan local governments. Over the medium to long term, it will establish dedicated units headed by private-sector experts to build specialized capacity.
The government will also identify and document baseline budget requirements for information security activities based on the characteristics of individual information systems, and will consult with related ministries on ways to encourage stable cybersecurity budget investment.
thlee@heraldcorp.com
