테러방지법 제2조 제1호상 테러의 법정 요건과 적용경계 : 사이버공격·전자기펄스(EMP) 공격의 포섭과 규범적 간극
The Statutory Requirements and Limits of the Definition of “Terrorism” under Article 2, Subparagraph 1 of the Anti-Terrorism Act : Its Applicability to Cyberattacks and Electromagnetic Pulse (EMP) Attacks and the Normative Gap
Purpose: In contemporary society, terrorist threats have evolved into complex forms, including physical attacks, cyberattacks, and electromagnetic pulse (EMP) attacks, particularly targeting national critical infrastructure and multi-use facilities. Due to their openness and accessibility, multi-use facilities are structurally vulnerable as “soft targets.” However, the current legal framework under the Act on Anti-Terrorism for the Protection of Citizens and Public Security and related regulations largely imposes only non-binding obligations on facility operators, thereby limiting the effectiveness of preventive safety management. This study aims to analyze the structural limitations of the existing terrorism safety management system and physical security framework and to propose institutional development strategies for a preventive, risk-based terrorism safety management system. In particular, this study focuses on the institutionalization of a terrorism risk assessment system as a central mechanism for strengthening preventive safety governance, while also considering the evolving threat environment, including North Korea’s EMP and cyber warfare capabilities. Methods: This study examines the legal framework governing terrorism safety management, including the Act on Anti-Terrorism for the Protection of Citizens and Public Security, its Enforcement Decree, and related administrative regulations, with particular emphasis on the designation and safety management obligations of terrorism target facilities. It also analyzes the operational limitations of physical security systems in national critical infrastructure and multi-use facilities, as well as the implications of emerging threats such as EMP and cyberattacks. Furthermore, international risk management standards, including ISO 31000 (Risk Management) and ISO 22320 (Emergency Management), are reviewed to assess their applicability to terrorism safety management. Based on this normative and institutional analysis, the study proposes a legal and institutional framework for the implementation of a terrorism risk assessment system. Results: The analysis reveals that the current terrorism safety management system lacks sufficient legal enforceability, as facility owners and operators are primarily subject to general duties of care rather than mandatory legal obligations. In addition, fragmented governance across multiple administrative authorities has resulted in inconsistencies in safety standards and varying levels of physical security protection. The inherent openness of multi-use facilities, combined with limited authority and expertise of private security personnel and insufficient budgetary and human resources, further constrains effective prevention and response capabilities. Moreover, emerging threats such as EMP and cyberattacks pose systemic risks that could disrupt national critical infrastructure, demonstrating the limitations of conventional physical security approaches. To address these challenges, this study proposes the following institutional reforms: ▲ the establishment of mandatory legal safety standards for terrorism target facilities, ▲ the institutionalization of a terrorism risk assessment system to enable risk-based preventive safety management, ▲ the strengthening of integrated counterterrorism governance across public and private sectors, and ▲ the enhancement of national infrastructure protection systems against EMP and cyber threats. Conclusion: Terrorism safety management must be reconceptualized not merely as a matter of physical protection but as a preventive legal and institutional framework grounded in the state’s constitutional obligation to protect life and safety. Transitioning from a recommendation-based system to a mandatory, risk-based safety management regime is essential for ensuring effective protection of terrorism target facilities, particularly multi-use and privately operated critical infrastructure. The institutionalization of a terrorism risk assessment system would enable systematic identification, evaluation, and mitigation of vulnerabilities, thereby enhancing the preventive capacity of the national safety framework. Given the persistent and evolving threat environment, including North Korea’s asymmetric capabilities, establishing an integrated, preventive risk management system is a constitutional and institutional imperative. Ultimately, terrorism safety management must evolve from a reactive, incident-driven approach to a proactive, system-based legal framework centered on risk assessment and prevention, thereby ensuring the effective protection of national security and human life in the modern security environment.
한국어
연구목적: 현대 사회에서 테러 위협은 국가중요시설과 다중이용시설을 중심으로 물리적 공격, 사이버 공격, 전자기펄스(EMP) 공격 등 복합적 양상으로 진화하고 있으며, 특히 개방성과 접근성이 높은 다중이용시설은 구조적으로 테러에 취약한 ‘Soft Target’으로 평가되고 있다. 그러나 현행 「국민보호와 공공안전을 위한 테러방지법」 및 관련 법령은 테러대상시설의 안전관리 의무를 주로 권고 수준에 머물게 하고 있어, 실효적 예방체계로 기능하는 데 한계를 보이고 있다. 본 연구는 현행 테러안전관리 법제와 물리적 보안체계의 구조적 한계를 분석하고, 특히 북한의 EMP 및 사이버테러 위협이라는 안보환경의 특수성을 고려하여, 예방 중심의 테러안전관리체계로 전환하기 위한 제도적 발전방안을 제시하는 것을 목적으로 한다. 특히 테러위험성평가제도의 제도화를 중심으로 법적·제도적 개선 방향을 규범적으로 정립하고자 한다. 연구방법: 본 연구는 「국민보호와 공공안전을 위한 테러방지법」, 동 시행령 및 관련 행정규범을 중심으로 테러대상시설의 지정과 안전관리 의무의 법적 구조를 분석하였다. 또한 국가중요시설 및 다중이용시설의 물리적 보안체계 운영 실태와 제도적 한계를 검토하고, 북한의 EMP 공격 및 사이버테러 위협이 국가기반시설 안전에 미치는 영향을 분석하였다. 아울러 ISO 31000(위험관리), ISO 22320(비상관리) 등 국제 위험관리 표준을 참고하여 위험기반 안전관리체계의 제도적 도입 가능성을 검토하고, 이를 바탕으로 테러위험성평가제도의 법제화 방안을 규범적으로 제시하였다. 연구결과: 분석 결과, 현행 테러안전관리체계는 시설 관리자에게 테러취약요인 제거를 위한 노력의무만을 부과하고 있어 법적 강제성과 집행력이 제한적이며, 시설 유형별 관리체계의 분산으로 인해 통합적 안전관리 기준이 확립되지 못하고 있음이 확인되었다. 또한 다중이용시설의 개방성과 민간 경비인력의 권한 제한, 예산 및 전문성 부족 등으로 인해 물리적 보안 대응에는 구조적 한계가 존재하였다. 특히 북한의 EMP 및 사이버 공격은 기존 물리적 보안 중심의 대응체계를 무력화할 수 있는 새로운 유형의 위협으로, 국가기반시설의 기능 안정성을 근본적으로 위협할 수 있음이 확인되었다. 이에 따라 다음과 같은 제도 개선방안을 제시하였다. ▲테러대상시설에 대한 법적 안전기준의 구체화 및 의무화, ▲테러위험성평가제도의 법제화를 통한 위험기반 예방관리체계 구축, ▲국가기관과 민간부문 간 통합적 대테러 거버넌스 강화, ▲EMP 및 사이버테러 대응을 위한 국가기반시설 보호체계의 제도적 강화이다. 결론: 테러안전관리는 단순한 물리적 방어 조치의 문제가 아니라, 국가의 생명·안전 보호의무에 기초한 예방 중심의 법적·제도적 관리체계로 재구성되어야 할 공법적 과제이다. 비교적 개방적 구조를 가지는 다중이용시설과 민간 기반시설에 대한 안전관리체계를 권고 중심에서 법적 의무 중심으로 전환하고, 테러위험성평가제도를 제도화함으로써 위험 수준에 따른 차등적 예방조치를 가능하게 해야 한다. 특히 북한의 복합적 테러 위협이 상존하는 대한민국의 안보환경을 고려할 때, 국가 차원의 통합적 위험관리체계를 구축하는 것은 헌법상 국민의 생명과 안전 보호의무를 실질적으로 구현하기 위한 필수적 조건이다. 궁극적으로 테러안전관리체계는 사후 대응 중심의 보안체계를 넘어, 위험의 사전 식별·평가·통제를 핵심으로 하는 예방 중심의 법적 안전관리체계로 발전되어야 하며, 이는 국가안전보장과 국민의 생명 보호를 조화시키는 현대 국가의 핵심적 책무로 자리매김되어야 할 것이다.
목차
ABSTRACT 요약 서론 테러방지법상 테러의 법정 요건과 적용경계 테러방지법 제2조 제1호의 규범적 성격: 정의조항의 이중적 기능 목적요건 객관적 행위유형 행위주체와 테러단체의 구별 사이버공격·EMP 등 복합위협의 법률상 규율과 「테러방지법」상 포섭의 한계 결론 및 제언 References
신유리 [ Yulee Shin | Senior Research Fellow, Institute of Legal Studies, Kookmin University/Adjunct Professor, Department of Police Science, Semyung University ]
Corresponding Author