Menu Content
Go Top

Domestic

Gov’t to Tighten Oversight of Certified Information Security Systems

Written: 2025-12-07 11:10:16Updated: 2025-12-07 11:26:46

Gov’t to Tighten Oversight of Certified Information Security Systems

Photo : YONHAP News

Amid recurring data breaches at companies with government-certified information security systems, the government has decided to significantly tighten management and auditing processes for those systems.

The Personal Information Protection Commission and the Ministry of Science and ICT on Saturday discussed ways to enhance the oversight of the Information Security Management System, or ISMS, and ISMS-P. 

Under the plan, the ISMS-P, which currently operates on a voluntary basis, will become mandatory for key organizations in the public and private sectors, including telecom companies and large-scale platform operators. 

New, stronger certification criteria will be devised for companies with significant public impact.

In the event of a data leak at a certified company, a special post-incident audit will follow, and companies might lose their certification for serious breaches of compliance with certification requirements.

Editor's Pick

Close

This website uses cookies and other technology to enhance quality of service. Continuous usage of the website will be considered as giving consent to the application of such technology and the policy of KBS. For further details >