|
Résumé :
|
This contribution presents the Republic of Korea's Information Security Management System (ISMS) and Personal Information & Information Security Management System (ISMS-P) certification framework as a statutory, government-administered cybersecurity assurance practice. Specified telecommunications operators, data-centre operators and information-service providers meeting prescribed statutory criteria are required to obtain management-system certification and may satisfy this requirement through either ISMS or ISMS-P certification. ISMS-P extends ISMS by incorporating additional requirements for personal-information processing and protection. The contribution describes the legal and institutional basis, mandatory scope, certification-criteria structure, relationship with ISO/IEC 27001, and certification lifecycle, and identifies lessons that may assist administrations in establishing national cybersecurity assurance frameworks for the telecommunications/ICT sector. It responds to the first output report of Question 3/2 (2027), which addresses cybersecurity public policies and regulations applicable to the telecommunications/ICT sector, including obligations, measures and assurance practices.
|