What South Korea Act on Promotion of Information and Communications Network Utilization and Information Protection 2001 (정보통신망법, Act No. 6360, as amended) requires
The Act on Promotion of Information and Communications Network Utilization and Information Protection (정보통신망 이용촉진 및 정보보호 등에 관한 법률 - Network Act or ICT Network Act) is South Korea's foundational statute governing cybersecurity obligations, information security management, internet service provider (ISP) obligations, and online communications regulation. Originally enacted as Act No. 6360 on 16 January 2001, the Network Act has been substantially amended multiple times and remains one of the primary cybersecurity and online content regulatory instruments in South Korea, operating in tandem with the Personal Information Protection Act 2023 (PIPA 2023) and the Information Security Industry Act. The Network Act is administered by the Ministry of Science and ICT (MSIT / 과학기술정보통신부) with technical cybersecurity oversight delegated to the Korea Internet Security Agency (KISA / 한국인터넷진흥원). Information security management system (ISMS) certification: Article 47 of the Network Act requires mandatory Information Security Management System (ISMS - 정보보호 관리체계) certification for ISPs exceeding revenue, user, or traffic thresholds - specifically: ISPs with annual information and communications service revenue of at least KRW 10 billion; ISPs with more than one million daily active users for three consecutive months; data centre operators (internet data centres / IDCs) regardless of size; hospitals, schools, and other designated entities specified by MSIT decree. ISMS-P (Information Security Management System - Personal Information) certification combines the ISMS framework with PIPA 2023 personal information protection requirements into a unified certification. Security incident reporting: Article 48-2 of the Network Act requires that ISPs notify KISA of significant security incidents within 24 hours of discovery. Incidents triggering mandatory reporting include: distributed denial of service (DDoS) attacks causing service disruption; system intrusions and unauthorised access causing data exposure; and ransomware or malware infections affecting critical systems. KISA coordinates incident response and may direct ISPs to implement containment measures. Prohibition on illegal content: Article 44-7 prohibits transmission or distribution of illegal information via information and communications networks, including information violating privacy, criminal defamation, obscene content, gambling operations, and content inciting violence or discrimination. The Korea Communications Standards Commission (KCSC) may order takedown of illegal content. Spam and unsolicited commercial communications: Article 50 prohibits sending unsolicited commercial electronic communications (email, SMS, push notifications) without prior consent of the recipient (opt-in regime); recipients must be provided with a clear opt-out mechanism; commercial emails must include the advertiser's identity and a no-cost opt-out method; violation of Art. 50 is subject to fines of up to KRW 30 million. Unauthorised access: Article 48 prohibits unauthorised access to or interference with information and communications systems; criminal sanctions include imprisonment of up to five years or a fine of up to KRW 50 million. Administrative fines (과태료) up to KRW 100 million are available for a range of Network Act violations. The 2020 amendment to the Network Act transferred primary personal data protection obligations (consent, notification, rights) from the Network Act to the Personal Information Protection Act (PIPA), maintaining the Network Act's focus on network security, ISMS certification, incident reporting, and online content regulation.
Pillar: Cybersecurity · Authority: Ministry of Science and ICT (MSIT / 과학기술정보통신부); Korea Internet Security Agency (KISA / 한국인터넷진흥원); Korea Communications Standards Commission (KCSC) · Version: 1.0.0 · Last updated:
Primary source: https://www.msit.go.kr/eng/
SHA-256 integrity: 380fb72b3577669757d542221523d7d373efb56ee51f500c4b5217a0ac63c18b
Primary Citations — 7 traced to source
- Act on Promotion of Information and Communications Network Utilization and Information Protection (정보통신망법, Network Act, Act No. 6360 of 16 January 2001, as amended) (South Korea) - foundational cybersecurity and ICT regulation statute; mandatory ISMS certification (Art. 47), security incident reporting (Art. 48-2), illegal content prohibition (Art. 44-7), and spam opt-in requirement (Art. 50)
- Network Act (South Korea), Art. 47 - mandatory ISMS certification for ISPs with KRW 10 billion annual revenue or 1 million daily users for 3 consecutive months, all IDC operators, and designated entities; certification issued by KISA; annual surveillance audits; full recertification every 3 years
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/kr-network-act-ict-2001.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/kr-network-act-ict-2001.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/kr-network-act-ict-2001
- Back to registry: Browse all 10,085 compliance nodes