South Korea’s POSCO E&C said on Thursday that it obtained the “Information Security Management System & Personal Information Protection Management System Certification” (ISMS-P), the highest-level information protection certification in the country by the Korea Internet & Security Agency (KISA).
The ISMS-P certification assesses whether a company can effectively respond to cyber threats and whether its information security system and personal information protection management system are properly operated.
To receive the ISMS-P certification, a company must pass an evaluation of 101 criteria, which cover areas such as management system policies, operation, and improvement; technical protection measures like asset management and security systems; and personal information lifecycle protection measures such as the collection, use and destruction of personal data.
POSCO E&C already holds the ISO27001 certification, an international standard for information security management systems, and with the addition of the ISMS-P certification, it now maintains one of the highest levels of information security and personal data protection in the country.
The company conducts rigorous security checks, including frequent simulated hacking attempts on all internal and external systems.
By Hyeon-woo Oh
ohw@hankyung.com