Skip to main content
Law4Kor
Electronic Financial Transactions Act

전자금융거래법

Article 21-3 (Analysis and Evaluation of Vulnerabilities of Electronic Financial Infrastructure)

제21조의3 전자금융기반시설의 취약점 분석ㆍ평가

Ministry
금융위원회
In force
2026-12-17
Articles
71
Original (Korean)

금융회사 및 전자금융업자는 전자금융거래의 안전성과 신뢰성을 확보하기 위하여 전자금융기반시설에 대한 다음 각 호의 사항을 분석ㆍ평가하고 그 결과(「정보통신기반 보호법」 제9조에 따른 취약점 분석ㆍ평가를 한 경우에는 그 결과를 말한다)를 금융위원회에 보고하여야 한다.

  1. 1. 정보기술부문의 조직, 시설 및 내부통제에 관한 사항

  2. 2. 정보기술부문의 전자적 장치 및 접근매체에 관한 사항

  3. 3. 전자금융거래의 유지를 위한 침해사고 대응조치에 관한 사항

  4. 4. 그 밖에 대통령령으로 정하는 사항

Financial companies and electronic financial service providers shall analyze and evaluate the following matters concerning electronic financial infrastructure in order to ensure the safety and reliability of electronic financial transactions, and report the results (in cases where vulnerability analysis and evaluation under Article 9 of the 「Information and Communication Infrastructure Protection Act」 has been conducted, the results thereof) to the Financial Services Commission. 1. Matters concerning the organization, facilities, and internal control of the information technology sector 2. Matters concerning electronic devices and access media of the information technology sector 3. Matters concerning measures to respond to security incidents for the maintenance of electronic financial transactions 4. Other matters prescribed by Presidential Decree

금융회사 및 전자금융업자는 제1항에 따른 전자금융기반시설의 취약점 분석ㆍ평가 결과에 따른 필요한 보완조치의 이행계획을 수립ㆍ시행하여야 한다.

Financial companies and electronic financial service providers shall establish and implement an action plan for necessary supplementary measures based on the results of the analysis and evaluation of vulnerabilities of electronic financial infrastructure under paragraph ①.

금융위원회는 소속 공무원으로 하여금 제1항에 따른 전자금융기반시설의 취약점 분석ㆍ평가 결과 및 제2항에 따른 보완조치의 이행실태를 점검하게 할 수 있다.

The Financial Services Commission may have its officials inspect the results of the analysis and evaluation of vulnerabilities of electronic financial infrastructure under paragraph ① and the implementation status of supplementary measures under paragraph ②.

제1항에 따른 전자금융기반시설의 취약점 분석ㆍ평가의 내용 및 절차와 제2항에 따른 이행계획의 수립ㆍ시행, 그 밖에 필요한 사항은 대통령령으로 정한다.

The details and procedures for the analysis and evaluation of vulnerabilities of electronic financial infrastructure under paragraph ①, the establishment and implementation of the action plan under paragraph ②, and other necessary matters shall be prescribed by Presidential Decree.

Translation

Machine translation. The Korean text is authoritative.

Statute text is reproduced from 법제처 국가법령정보센터. This is information, not legal advice.

Electronic Financial Transactions Act 제21조의3 — Article 21-3 (Analysis and Evaluation of Vulnerabilities of Electronic Financial Infrastructure) · Law4Kor