논문 상세보기

선박 사이버위기 경보발령의 행정처분성 확보를 위한 입법론 KCI 등재

A Legislative Proposal to Secure the Administrative Disposition Status of Ship Cyber Crisis Alerts

배수빈
  • 언어KOR
  • URLhttps://db.koreascholar.com/Article/Detail/451907
구독 기관 인증 시 무료 이용이 가능합니다. 7,000원
海事法硏究 (해사법연구)
한국해사법학회 (The Korea Institute Of Maritime Law)
초록

해사 사이버안전 법체계에서 선박소유자의 사이버 사고대응에 관한 규율은 해사 사이버안전 관리지침이 담당하고 있다. 해사 사이버안전 관리지침은 IMO MSC-FAL.1/Circ.3의 5가지 기능 체계에 따라 선박소유자의 관리 의무를 규정 하고 있으나, 위기 상황에서 해양수산부장관이 경보를 발령하고 선박소유자에 게 법적 의무를 부과할 수 있는 근거는 존재하지 않는다. 따라서 이 연구는 해사 분야에 경보권한이 필요한 근거를 제시한다. 현행 경 보체계는 발령 권한을 공공·민간·국방으로 나눈다. 그러나 발령 권한 체계에 해양수산부장관의 경보 권한은 없다. 선박운항시스템이 해킹되면 정보유출에 그치지 않고 충돌·좌초로 이어져 인명과 해양환경을 해친다. 충돌 및 좌초로 이어지는 물리적 위험은 데이터 손상을 주로 다루는 경보 체계가 포섭하지 못 한다. 또한 대응체계는 고정된 위치와 국내 관할을 전제로 설계되어 있으나 선 박은 전 세계를 운항하므로, 선박이 국내 관할 밖에 있을 때에는 경보가 실시 간으로 미치기 어렵다. 나아가 IMO MSC.428(98) 결의로 해사 사이버안전을 선박 안전의 독립된 규 율영역으로 확립하였다. 육상의 일반 산업에는 이러한 국제적 규율이 없다. 물 리적 위험·국제적 이동성·국제 규범의 독립성을 갖는 해사 사이버위험은 육상 의 일반 정보위험과 구별되므로, 해사 분야의 독자적 경보권한은 특정 부처의 권한 확대가 아니라 위험의 특수성에 대응하기 위한 규율이다. 경보발령의 공백은 이중의 구조를 가지고 있다. 해사 사이버안전 확보를 위 한 대응조치는 수범자를 선박소유자로 한정하고 행정청의 역할을 규정하지 않 는다. 또한 국가사이버안전관리규정에서의 경보발령은 발령 주체를 국가정보 원장·과학기술정보통신부장관·국방부장관으로 한정하여, 해양수산부장관을 명 시적으로 포함하고 있지 않다. 경보발령의 두 공백이 결합하여 해사 사이버 위 기가 발생하였을 경우 어떠한 행정청도 선박소유자에게 법적으로 유효한 경보 를 발령할 수 없는 상태에 있다. 이 연구는 경보발령 공백의 쟁점을 검토하고 입법적 개선방안을 모색하고자 한다. 해사 사이버안전 관리지침과 국가사이버안전관리규정은 행정규칙에 해 당하여 행정기관 내부에서만 효력을 가질 뿐 선박소유자와 같은 민간에 대하여 는 법적 구속력이 없다. 따라서 해양수산부장관이 경보를 발령하더라도 경보발 령은 행정소송의 대상이 되는 행정처분으로 볼 수 없다. 또한 경보발령이 행정 처분에 해당하는지, 행정절차법상 사전통지가 요구되는지, 선박소유자가 불복 할 수 있는지에 관한 규율이 마련되어 있지 않아 법률유보 원칙과 적법절차 원 칙에도 위반된다. 행정처분성은 두 측면에서 검토된다. 첫째는 현행 법령의 해석상 경보발령이 행정지도·사실행위·권고적 경고와 구별되지 않아 처분성이 부정된다는 점이고, 둘째는 입법을 통하여 경보단계를 선박소유자의 이행 의무와 연동시킴으로써 경보발령을 행정처분으로 구성하여야 한다는 점이다. 따라서 이 연구의 행정처 분성 확보란 현행법상 처분성이 있다는 뜻이 아니라, 입법을 통하여 갖추어야 한다는 의미이다. 이에 단기적으로 해사 사이버안전 관리지침의 대응조치에 행정청의 역할을 명시하는 개정안을 제시하고, 중·장기적으로 특별법을 통한 법률적 수권·행정 처분성 명시·적법절차 요건 구체화를 제안하고자 한다.

In the maritime cyber safety regime, the regulation of shipowners’ responses to cyber incidents is governed by the Maritime Cyber Safety Management Guidelines. The Guidelines prescribe shipowners’ management obligations in accordance with the five functional elements of IMO MSC-FAL.1/Circ.3, yet they provide no basis on which the Minister of Oceans and Fisheries may, in a crisis, issue an alert and impose legal obligations on shipowners. This study demonstrates why an alert-issuance authority is required in the maritime sector. The current alert system divides the issuing authority among the public, private, and defense sectors, and the Minister of Oceans and Fisheries holds no alert authority within this structure. Where a ship operation system is compromised, the harm is not confined to data breaches but extends to collisions and groundings that endanger human life and the marine environment. Such physical risks are not captured by an alert system oriented primarily toward data compromise. Moreover, the response system presupposes a fixed location and domestic jurisdiction, whereas ships operate worldwide; an alert therefore cannot reach a ship in real time once it lies beyond domestic jurisdiction. IMO Resolution MSC.428(98) has established maritime cyber safety as an independent regulatory domain, imposing an international obligation not placed on industry in general. Maritime cyber risk, characterized by physical danger, international mobility, and the independence of international norms, is distinct from ordinary information risk ashore. An independent alert authority for the maritime sector is thus not an expansion of a particular ministry’s power but a regulation responding to the distinctive nature of the risk. The gap in alert issuance has a dual structure. The response measures for maritime cyber safety confine their addressees to shipowners and do not provide for the role of the administrative authority. The National Cyber Security Management Regulation, in turn, limits the authority to issue alerts to the Director of the National Intelligence Service, the Minister of Science and ICT, and the Minister of National Defense, and does not expressly include the Minister of Oceans and Fisheries. As these two gaps combine, no administrative authority can issue a legally valid alert to shipowners when a maritime cyber crisis arises. This study examines the issues arising from the gap in alert issuance and explores legislative improvements. The Maritime Cyber Safety Management Guidelines and the National Cyber Security Management Regulation are administrative rules that take effect only within administrative organs and have no binding force on private parties such as shipowners. Accordingly, even if the Minister of Oceans and Fisheries issues an alert, the issuance cannot be regarded as an administrative disposition subject to administrative litigation. Furthermore, because no provision governs whether the issuance constitutes an administrative disposition, whether prior notice under the Administrative Procedures Act is required, or whether shipowners may contest it, the current framework violates the principle of statutory reservation and the principle of due process. The administrative disposition status is examined in two dimensions. First, under the interpretation of current law, the alert is not distinguished from administrative guidance, factual acts, or advisory warnings, and its disposition status is therefore denied. Second, through legislation, the alert should be constructed as an administrative disposition by linking each alert level to the shipowner’s compliance obligations. Securing the administrative disposition status in this study thus does not mean that such status exists under current law, but that it must be established through legislation. To this end, this study proposes, in the short term, an amendment specifying the role of the administrative authority within the response measures of the Maritime Cyber Safety Management Guidelines, and, in the medium to long term, special legislation that confers statutory authorization, expressly establishes the administrative disposition status, and specifies the requirements of due process.

키워드
해사 사이버안전 관리지침사이버위기경보행정처분성법 률유보 원칙적법절차 Maritime Cyber Safety Management GuidelinesCyber Crisis AlertAdministrative DispositionPrinciple of Statutory ReservationDue Process.
목차
<목 차>
국문초록
Abstract
Ⅰ. 서 론
Ⅱ. 해사 사이버안전 관리체계 및 경보발령의 현황
    1. 해사 사이버안전 관리지침의 개념과 법적 성격
    2. 해사 사이버안전 관리의 대응조치와 기능적 요소
    3. 국가사이버안전관리규정의 경보발령 체계
    4. IMO 규범 체계와의 관계
Ⅲ. 경보발령의 행정법적 공백
    1. 경보발령 권한의 부재
    2. 경보발령 행위의 행정처분성 결여
    3. 법률유보 및 적법절차 원칙의 위반
    4. 사고통보 의무 문제
Ⅳ. 경보발령의 입법적 개선방안
    1. 경보발령 권한의 수권
    2. 경보발령의 행정처분성
    3. 적법절차 요건
    4. 사고통보 의무
    5. 조문안 제시
Ⅴ. 결 론
참 고 문 헌
저자
  • 배수빈(목포해양대학교 해양경찰학부 강사, 법학박사.) | Soo-Bin Bae