Certification · Last verified
Personal Information & Information Security Management System
ISMS-P is South Korea's integrated certification for information security and personal-data management, statutory for defined ICT operators. Its criteria set has 102 requirements — set-up and operation, protection measures, and personal-data processing steps — and certification is operated by KISA, with FSI certifying in the financial sector.
- Class
- Certification
- Owner
- Policy: Ministry of Science and ICT and the Personal Information Protection Commission (PIPC); certification bodies: Korea Internet & Security Agency (KISA) and Financial Security Institute (FSI)
- Public register
- Verified working
- Last verified
What it is
ISMS-P is South Korea's integrated certification for information security and personal-data management: the PIPC describes it as the scheme that consolidated the previously separate PIMS (Personal Information Management System) and ISMS (Information Security Management System) certifications from 7 November 2018. Its criteria set has 102 requirements — 16 on the set-up and operation of the control system, 64 protection-measure requirements, and 22 covering personal-data processing steps; the last 22 are what separate ISMS-P from plain ISMS. Certification is operated by KISA, with FSI certifying in the financial sector, and reviews carried out by KAIT, TTA and OPA.
Who owns it
The certification is operated by the Korea Internet & Security Agency (KISA), with the Financial Security Institute (FSI) certifying in the financial sector, under policy set by the Ministry of Science and ICT and the Personal Information Protection Commission (PIPC).
Who assesses it
The PIPC's English page gives the institutional structure: certification bodies are KISA and, in the financial sector, FSI; review bodies are the Korea Association for ICT Promotion (KAIT), the Telecommunications Technology Association (TTA) and the Online Privacy Association (OPA); results are evaluated by a Certification Committee.
Who asks for it
Statutory (scoped). Statutory in one defined scope: article 47(2) of Korea's Act on Promotion of Information and Communications Network Utilization and Information Protection obliges telecommunications business entities, major providers of information and communications services, data centre operators and providers above set thresholds to obtain ISMS certification. The obligation as verified attaches to the ISMS certification; whether the combined ISMS-P certification is required of anyone was not verified. Outside that scope this record documents no verified demand driver.
For part of the market this is law. Article 47(2) of the Act on Promotion of Information and Communications Network Utilization and Information Protection requires certification from "a telecommunication business entity under subparagraph 8 of Article 2 of the Telecommunications Business Act", from "a major provider of information and communications services", from "a data center operator", and from "a person meeting the standards prescribed by Presidential Decree, whose sales, tax revenue, or any similar for the previous year is at least 150 billion won, whose sales in the information and communications service sector for the previous year is at least 10 billion won, or whose average daily users for the previous year is at least one million". These are the official English translation's words; the Korean original is the binding text. The obligation as verified is for ISMS certification — whether the combined ISMS-P certification is separately required was not verified in the sources reviewed as of 29 August 2026; confirm against MSIT and PIPC.
Validity
The period of validity of the certification of an information security management system under paragraph (1) shall be three years. (Network Act art. 47(5), official English translation; the Korean original is the binding text. This provision covers ISMS certification — the validity period specific to the combined ISMS-P certification was not separately verified.)
Sources
- PIPC — ISMS-P (scheme authority, English page) ↗ — accessed
- Korea Legislation Research Institute — official English translation, Network Act art. 47 ↗ — accessed
- ISMS-P — public list of issued certificates (Korean) ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.