SEOUL METROPOLITAN GOVERNMENT ORDINANCE ON CYBERSECURITY
| Enactment No. 9889, Sep. 29, 2025 | |
|---|---|
|
|
Article 1 (Purpose)
The purpose of this Ordinance is to prescribe the matters required to strengthen cybersecurity and to improve and enhance the systems of cooperation between the relevant institutions so as to enable the latter to respond systematically and effectively to cyber-attacks and threats, and to prescribe the matters delegated by the Regulations on Cybersecurity Services.
|
|
|
Article 2 (Definition of Terms)
The definitions of the terms used in this Ordinance shall be as follows:
|
|
|
Article 3 (Responsibility)
(1) The Seoul Metropolitan City Mayor (hereinafter referred to as the “Mayor”) and the heads of agencies at various levels shall make efforts to protect cyberspace from cyber-attacks and threats.
|
|
|
Article 4 (Applicability)
This Ordinance shall apply to the cybersecurity services of the agencies at various levels, etc. of the Seoul Metropolitan Government.
|
|
|
Article 5 (Scope of Public Institutions Subject to Cybersecurity Duties)
“Institutions prescribed by Municipal Ordinance” in Article 7 (2) 2 of the Regulations on Cybersecurity Services refers to invested or funded institutions established by the investment or funding of Seoul Metropolitan Government and designated and publicly notified under Article 5 of the Act on the Operation of Local Government-Invested or -Funded Institutions.
|
|
|
Article 6 (Operation of a Cybersecurity Managing Officer)
(1) To ensure the efficient and systematic performance of cybersecurity duties and the safe protection of the affairs under his or her jurisdiction, the Mayor shall secure appropriate personnel with expert knowledge in cybersecurity to form and operate a dedicated cybersecurity organization.
|
|
|
Article 7 (Operation of Assistant Cybersecurity Management Officers)
(1) To ensure the cybersecurity management officer’s efficient performance of his or her duties, the Mayor shall appoint and assign an assistant cybersecurity management officer to each department and appoint assistant cybersecurity officers to assist them. Matters necessary for the foregoing - such as the assistant cybersecurity management officer’s qualifications, appointment procedures, and scope of duties - shall be determined by the relevant rules.
|
|
|
Article 8 (Formulation of Basic Plans)
To ensure the efficient implementation of cybersecurity duties, the Mayor shall formulate and implement a Seoul Metropolitan City Cybersecurity Basic Plan (hereinafter the “Basic Plan”) every five years, which shall include the following matters:
|
|
|
Article 9 (Formulation of Implementation Plans)
(1) The Mayor shall formulate and implement annual implementation plans for cybersecurity duties in keeping with the Basic Plans under Article 8.
|
|
|
Article 10 (Establishment and Functions of the Cybersecurity Advisory Committee)
The Mayor may establish the Seoul Metropolitan Government Cybersecurity Advisory Committee (hereinafter referred to as the “Committee”) to advise on implementing the following cybersecurity services:
|
|
|
Article 11 (Committee Composition)
(1) The Committee shall be composed of 15 or fewer members including one Chairperson and two Vice-Chairpersons, and the gender balance shall be considered in the composition.
|
|
|
Article 12 (Data Submission)
The Mayor may request the heads of agencies at various levels to submit data if necessary for the performance of cybersecurity services, such as self-diagnostics and inspections under Article 15, investigation of accidents under Article 19, cybersecurity audits under Article 25, and assessments of the actual state of cybersecurity under Article 13 of the Regulations on Cybersecurity Services. The heads of agencies at various levels who receive such requests shall comply in the absence of a justifiable cause for not doing so.
|
|
|
Article 13 (Cybersecurity Education)
(1)The Mayor and the heads of agencies at various levels shall implement at least one educational course per year as necessary to raise affiliated public officials’ (including civil servants and fixed-term employees; hereinafter the same shall apply) and employees’ awareness of the necessity and importance of cybersecurity and to enhance the work capabilities of affiliated public officials and employees who perform cybersecurity duties.
|
|
|
Article 14 (Preventative Cybersecurity Measures, Etc.)
(1) To prevent cyber-attacks and threats, the Mayor may review the security of informatization projects implemented at agencies at various levels, etc., and verify whether the results of such review are implemented by agencies at various levels, etc.
|
|
|
Article 15 (Cybersecurity Self-Diagnostics and Inspections)
(1) The Mayor shall implement, on an annual basis at the very least, self-diagnostics and inspections of the following, in order to prevent and respond to cyber-attacks and threats against agencies at various levels, etc.:
|
|
|
Article 16 (Strengthening Security for the Use of New TechnologiesSuch as Artificial Intelligence)
(1) When agencies at various levels, etc. seek to implement the following policies, they shall formulate security countermeasures and consult with the Mayor to identify security threats in advance and remove security vulnerabilities:
|
|
|
Article 17 (Establishment and Operation of Security Control Centers)
(1) The Mayor shall establish and operate the Security Control Center to detect and respond immediately to cyber-attacks and threats against agencies at various levels, etc. (hereinafter referred to as “security control”)
|
|
|
Article 18 (Issuance of Warnings)
(1) Where a warning has been issued under Article 15 of the Regulations on Cybersecurity Services, the Mayor and the heads of agencies at various levels shall take necessary measures according to the corresponding warning level, such as strengthening readiness against cyber-attacks and threats.
|
|
|
Article 19 (Accident Investigation and Reporting)
(1) In the event of accident caused by a cyber-attack or a threat against agencies at various levels, etc., the Mayor may investigate the accident in order to identify the perpetrator of the attack, analyze the cause, and confirm the details of any damages, etc.
|
|
|
Article 20 (Cybersecurity Restoration System)
(1) Depending on the severity of an accident, the Mayor may form and assign a Cybersecurity Emergency Countermeasures Team to minimize the damages resulting from an accident under Article 19.
|
|
|
Article 21 (Cyber-Attack and Threat Response Training)
(1) The Mayor and the heads of agencies at various levels shall implement, on an annual basis at the very least, training on how to respond to cyber-attacks and threats.
|
|
|
Article 22 (Sharing of Information on Cybersecurity Threats)
(1) To ensure the prevention of and rapid response to cyber-attacks and threats, the Mayor and the heads of agencies at various levels may share the following information (hereinafter referred to as “threat information”) between agencies:
|
|
|
Article 23 (Cooperation Systems)
The Mayor may implement the following matters in order to enhance cybersecurity levels and strengthen the systems for domestic and international cooperation:
|
|
|
Article 24 (Consultative Council)
(1) The Mayor may participate in a consultative council under Article 169 of the Local Autonomy Act in order to coordinate cybersecurity policies and promote information-sharing.
|
|
|
Article 25 (Cybersecurity Audits)
(1) The Mayor shall implement, on an annual basis at the very least, cybersecurity audits to investigate and inspect the cybersecurity services and activities of agencies at various levels, etc.; the standards and procedures for which shall be determined by the Mayor with reference to the guidelines presented in Article 3-2 (1) 2 of the Regulations on Cybersecurity Services.
|
|
|
Article 26 (Handling of Persons who Infringe the Cybersecurity Regulations)
The Mayor shall enact and implement standards for the handling of persons who have infringed the cybersecurity regulations.
|
|
|
Addendum <No. 9889, Sep. 29, 2025> |






