confidence building measures, suggested and adopted at the ISM, and prepared itself to
implement and develop the measures in cooperation with ARF Participants.
ㆍCapacity building efforts at the international, regional and bilateral levels
Countries with lower cyber security capacity are often targeted to be used as a transit route,
and the ROK views capacity development as one of top priorities in promoting ICTs security.
In line with the matter, the ROK included capacity building as a major item on the agenda for
the Global Conference on Cyber Space in Seoul in 2013.
Taking a step further, the ROK implemented various capacity building projects with
developing countries by setting the Global Cybersecurity Center for Development (GCCD) in
2015 and the Cybersecurity Alliance for Mutual Progress (CAMP) in 2016. Through the
projects, the ROK provided policy advice, consultations and trainings on cyber-security
measures to developing countries. Moreover, since 2015, the GCCD has hosted capacity
building seminars in 13 countries to offer practical information to the participants and relay
the ROK’s experience. The said CAMP, composed 59 agencies of 45 countries as its
members, has hosted four congresses and five regional forums so far.
(Norm 2) In case of ICT incidents, States should consider all relevant information,
including the larger context of the event, the challenges of attribution in the ICT
environment and the nature and extent of the consequences;
The ROK set up its own cross-governmental system to respond to future cyber threats. Under
the leadership of the Presidential Office, the Ministry of Science and Information (MSIT) is
in charge of responding to cyber threats targeting the private sector, whereas the National
Cyber Security Center (NCSC) manages the public sector, and the Ministry of National
Defense (MND) has a responsibility of the national defense.
In accordance with the National Cyber Security Management Regulation, the NCSC operates
the joint cyber threats response system by which relevant information is shared in real time,
and threat warnings and response guidelines are issued accordingly. Weekly cyber threats
index is also updated and notified to government institutions. Similarly, relevant agencies
have their own cybersecurity monitoring centers to detect and promptly respond to cyber
threats.
In efforts of considering all relevant information in case of ICT incidents, the ROK has
encouraged private entities to share information through public-private consultation meeting
in responding to ICT incidents since 2016 and the network of the Cyber Threats Intelligence
since 2014. The Cyber Security Big Data Center was also established by the Korea Internet &
Security Agency (KISA) in 2018. Thanks to its well-established network between the public
and private sectors, 260 companies reported and shared over 200 million cases on cyber
threats only in 2019.
3 / 10