[Veat Column] Introduction of Provisional Certification System for Virtual Asset Business Operators Regarding ISMS Certification

Article posted in 2022-05-24 16:34:35 | VEAT

To operate a cryptocurrency exchange, operate a cryptocurrency wallet service, or provide custody services, this falls under the “Act on Reporting and Use of Specific Financial Transaction Information” (hereinafter referred to as the “Specific Financial Transaction Act”) and requires obtaining a “Virtual Asset Business Operator” certification under Article 7, Paragraph 1. To do this, you must obtain an “Information Security Management System (ISMS) Certification” as defined in the “Notice on Information Security and Personal Information Protection Management System Certification,” and this ISMS certification.


Prior to the ISMS certification, to obtain certification, the Information Security Management System required operation for at least 2 months after establishing the system, making a successful audit possible. However, the Specific Financial Transaction Act required obtaining an ISMS certification at the notification stage before starting a virtual asset business, so submitting a record of at least 2 months of operation was impossible.


Therefore, the Korea Information and Communication Technology Industry Promotion Agency introduced the “Pre-Certification” system for new virtual asset business operators, and when there is no history of operating an Information Security Management System for 2 months, “Pre-Certification” is obtained, and a virtual asset business operator notification is submitted within 3 months of obtaining Pre-Certification, and an ISMS self-certification is obtained within 6 months after the virtual asset business operator notification is approved. This was announced for public comment on March 31, 2022.


 

Furthermore, unlike ISMS self-certification, the pre-certification scope is limited to the extent that the Information Security Management System can be verified through operational testing. Although detailed criteria have not yet been announced, it is expected that a simplified certification criteria will be applied, based on the certification criteria (Appendix 7) of the ISMS certification.


Therefore, a business starting a virtual asset business should establish an Information Security Management System to obtain Pre-Certification, and after receiving consultation on “Virtual Asset Business ISMS Certification” from a professional after scheduling the business implementation date, it is appropriate to apply for certification.

 

Furthermore, after obtaining Pre-Certification, in addition to the Specific Financial Transaction Act notification procedure and the ISMS self-certification procedure, it is necessary to continue to prepare for these processes.

 

For businesses starting a virtual asset business, they experience significant difficulties in developing business models and building systems. In addition to this, it is difficult to satisfy legal requirements such as the virtual asset business operator notification and ISMS certification. Notably, the details of the ISMS certification are reflected as “Administrative and Technical Certification Criteria” under the law and technology, so it is good to conduct the certification by verifying ISMS certification cases.

 

The author of this column, Mr. Baek Seung-cheol, Partner Attorney at Law Firm Veat, who has been certified as an “IT Specialist Attorney” after rigorous review by the Korea Bar Association’s Professional Specialty Registration Committee, and has successfully handled numerous personal information protection and infringement accident related lawsuits, also holds experience in providing personal information protection and infringement prevention lectures to various companies and public institutions.

 

Thank you.