I. Overview

%%{init: { 'theme': 'base', 'themeVariables': { 'edgeLabelBackground': '#fff' }}}%%
flowchart LR
    A["Separate\nsecurity management"] -- "integrating information security\nand personal information protection" --> B["Enterprise-wide\nsecurity governance"]
    style A fill:#f9f9f9,stroke:#333,stroke-width:3px
    style B fill:#e1f5fe,stroke:#01579b,stroke-width:3px

Definition: ISMS-P integrates the information security management system ( ISMS ) and the personal information management system ( PIMS ) into a single management system, and is Korea’s most comprehensive certification scheme, designed to let organizations respond to security threats on their own.

Background of the integration:
( Removing duplication ) Eliminates the overlap between two similar certification schemes ( ISMS + PIMS ), reducing the administrative burden on organizations.
( Governance integration ) Operates information security and personal information protection organically within a single management system, improving efficiency.
( Stronger security ) Strengthens the ability to respond to personal information breaches and secures legal compliance.

II. Mechanism & Components

Certification Framework

flowchart TD
    A["ISMS-P\nCertification Framework"] --> B["1. Establishing and Operating\nthe Management System\n(16 criteria)"]

    B --> C["2. Protection Measure\nRequirements\n(64 criteria)"]
    B --> D["3. Requirements by Stage of\nPersonal Information Processing\n(22 criteria)"]

    C --> C1["Personnel and\nPhysical Security"]
    C --> C2["Technical Security\nAccess Control / Encryption / Network"]
    C --> C3["Operational Security\nIncident Response / Business Continuity"]

    D --> D1["Collection, Use,\nand Provision"]
    D --> D2["Retention\nand Destruction"]
    D --> D3["Protection of\nData Subject Rights"]

Key point: Information security and personal information protection measures are organically linked, built on the establishment and operation of the management system.

Key Certification Criteria by Area

Certification AreaNumber of CriteriaKey Content
1. Establishing and Operating the Management System16Establishing the management system, risk management, operating the PDCA (Plan-Do-Check-Act) cycle
2. Protection Measure Requirements64Personnel security, physical security, network security, system access control, incident response
3. Requirements by Stage of Personal Information Processing22Protecting data subject rights and ensuring legal compliance during collection, use/provision, and destruction

III. Advanced Topics & Comparison

  • Expected benefits: Establishes organizational security governance, ensures legal compliance, and improves external credibility while reducing risk.
  • Future direction: With the recent spread of cloud services, ISMS-P needs closer linkage with CSAP (Cloud Security Assurance Program) and greater interoperability with global security standards such as ISO 27001.

Last updated 18 Aug 2026, 00:00 UTC. history