South Korea ISMS-P
Evidence request list. 25 controls, 25 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Access Control
Establish access control policies based on the principle of least privilege. Implement formal authorization procedures for system and information access.
- Approved governance policy with documented scope and accountabilities
- Board or steering committee minutes evidencing oversight
- Roles and responsibilities matrix (RACI)
- Access provisioning and review records
- Multi-factor authentication configuration evidence
- Privileged access management logs
- Policy document exists but lacks evidence of board approval or refresh cycle
- Accountabilities defined on paper but not reflected in performance objectives
- Privileged accounts not subject to regular re-certification
- Multi-factor authentication not enforced for all in-scope systems
- Statement of applicability lags behind risk assessment refresh
Manage user accounts throughout their lifecycle including creation, modification, periodic review, and deactivation. Implement unique identification for all users.
- Access provisioning and review records
- Multi-factor authentication configuration evidence
- Privileged access management logs
- ISMS-P scope statement and statement of applicability
- Annual ISMS-P internal audit report
- Management review minutes with corrective actions
- Privileged accounts not subject to regular re-certification
- Multi-factor authentication not enforced for all in-scope systems
- Statement of applicability lags behind risk assessment refresh
- Management review minutes record decisions without timed actions
Implement strong authentication mechanisms including password policies, multi-factor authentication for sensitive systems, and session management controls.
- Access provisioning and review records
- Multi-factor authentication configuration evidence
- Privileged access management logs
- ISMS-P scope statement and statement of applicability
- Annual ISMS-P internal audit report
- Management review minutes with corrective actions
- Privileged accounts not subject to regular re-certification
- Multi-factor authentication not enforced for all in-scope systems
- Statement of applicability lags behind risk assessment refresh
- Management review minutes record decisions without timed actions
Control network access through segmentation, firewall policies, VPN for remote access, and network monitoring. Restrict unauthorized network connections.
- Access provisioning and review records
- Multi-factor authentication configuration evidence
- Privileged access management logs
- ISMS-P scope statement and statement of applicability
- Annual ISMS-P internal audit report
- Management review minutes with corrective actions
- Privileged accounts not subject to regular re-certification
- Multi-factor authentication not enforced for all in-scope systems
- Statement of applicability lags behind risk assessment refresh
- Management review minutes record decisions without timed actions
- East-west traffic monitoring weaker than perimeter monitoring
Per ISMS-P: access control + cryptography + logging + audit + Korean specific encryption (SEED + ARIA).
- KR ISMS-P evidence for KRISMSP-3
- KISA certification + PIPC partial
Certification
Per ISMS-P: KISA certification + PIPC cooperation + 3-year recertification + maintenance reviews.
- KR ISMS-P evidence for KRISMSP-5
- KISA certification + PIPC partial
ISMS
Per South Korea ISMS-P (KISA): ISMS. Requirements include (a) Information Security and Privacy Management System + (b) Chief Information Security Officer Designation + (c) Information Asset Inventory and Classification + (d) Risk Assessment and Treatment + (e) KISA certification.
- KR ISMS-P evidence for KRISMSP-1
- KISA certification + PIPC partial
Incident Response
Per ISMS-P + PIPA: incident response + breach notification to PIPC + KISA + affected subjects.
- KR ISMS-P evidence for KRISMSP-4
- KISA certification + PIPC partial
Management System
Establish an information security policy approved by top management. Designate a CISO and establish an information security organization with clear roles and responsibilities.
- Approved governance policy with documented scope and accountabilities
- Board or steering committee minutes evidencing oversight
- Roles and responsibilities matrix (RACI)
- ISMS-P scope statement and statement of applicability
- Annual ISMS-P internal audit report
- Management review minutes with corrective actions
- Policy document exists but lacks evidence of board approval or refresh cycle
- Accountabilities defined on paper but not reflected in performance objectives
- Statement of applicability lags behind risk assessment refresh
- Management review minutes record decisions without timed actions
Establish and implement a risk management process including asset identification, threat and vulnerability assessment, risk analysis, and risk treatment plan development.
- Risk register with treatment plans and owner sign-offs
- Risk appetite statement approved by the board
- Periodic risk review reports
- ISMS-P scope statement and statement of applicability
- Annual ISMS-P internal audit report
- Management review minutes with corrective actions
- Statement of applicability lags behind risk assessment refresh
- Management review minutes record decisions without timed actions
- Documentation exists but lacks evidence of periodic refresh
Develop annual information security plans including objectives, resource allocation, implementation schedule, and performance metrics. Obtain top management approval.
- ISMS-P scope statement and statement of applicability
- Annual ISMS-P internal audit report
- Management review minutes with corrective actions
- Statement of applicability lags behind risk assessment refresh
- Management review minutes record decisions without timed actions
- Documentation exists but lacks evidence of periodic refresh
Conduct periodic management reviews of the information security management system. Monitor performance metrics and implement continuous improvement measures.
- ISMS-P scope statement and statement of applicability
- Annual ISMS-P internal audit report
- Management review minutes with corrective actions
- Post-incident review template completed for each major incident
- Improvement backlog with prioritisation and closure evidence
- Annual programme effectiveness review
- Statement of applicability lags behind risk assessment refresh
- Management review minutes record decisions without timed actions
- Improvement actions raised but closure evidence lacking
- Trend analysis across incidents not consistently performed
Personal Information Protection
Collect personal information only with the data subject's consent for specified purposes. Collect minimum information necessary. Provide clear privacy notices.
- ISMS-P scope statement and statement of applicability
- Annual ISMS-P internal audit report
- Management review minutes with corrective actions
- Statement of applicability lags behind risk assessment refresh
- Management review minutes record decisions without timed actions
- Documentation exists but lacks evidence of periodic refresh
Use personal information only for the specified purpose of collection. Secondary use requires additional consent or legal basis. Maintain records of processing activities.
- Records of processing activities (Article 30 style register)
- Lawful basis assessment per processing purpose
- Data minimisation review evidence
- ISMS-P scope statement and statement of applicability
- Annual ISMS-P internal audit report
- Management review minutes with corrective actions
- Records of processing activities outdated against current systems
- Lawful basis selections rely on consent where alternative is more defensible
- Statement of applicability lags behind risk assessment refresh
- Management review minutes record decisions without timed actions
Obtaining consent before providing personal information to third parties. When outsourcing processing, manage and supervise the outsourcee's handling of personal information.
- Third-party risk assessment dossier per vendor
- Signed contracts with required protection clauses
- Ongoing assurance reports (SOC 2, ISO, audit findings)
- ISMS-P scope statement and statement of applicability
- Annual ISMS-P internal audit report
- Management review minutes with corrective actions
- Vendor risk assessments not refreshed at the required cadence
- Subcontractor flow-down clauses absent or weak in contracts
- Statement of applicability lags behind risk assessment refresh
- Management review minutes record decisions without timed actions
- Concentration risk across critical suppliers not actively monitored
Inform data subjects and obtain consent before transferring personal information overseas. Ensure adequate protection measures at the receiving end.
- Transfer impact assessment records
- Standard contractual clauses and adequacy decision references
- Transfer register with safeguards documented
- ISMS-P scope statement and statement of applicability
- Annual ISMS-P internal audit report
- Management review minutes with corrective actions
- Transfer impact assessments missing for legacy data flows
- Standard contractual clauses not aligned to the current EU template version
- Statement of applicability lags behind risk assessment refresh
- Management review minutes record decisions without timed actions
Ensure data subjects can exercise their rights including access, correction, deletion, suspension of processing, and withdrawal of consent. Respond within legal timelines.
- Consent capture records with timestamps and scope
- Data subject request log with response evidence
- Privacy notice versions with change history
- ISMS-P scope statement and statement of applicability
- Annual ISMS-P internal audit report
- Management review minutes with corrective actions
- Consent capture mechanisms do not record granularity required by law
- Data subject request workflow exceeds statutory response deadlines
- Statement of applicability lags behind risk assessment refresh
- Management review minutes record decisions without timed actions
Destroy personal information without delay when retention period expires or purpose is achieved. Use methods that prevent recovery: physical destruction, overwriting, or degaussing.
- ISMS-P scope statement and statement of applicability
- Annual ISMS-P internal audit report
- Management review minutes with corrective actions
- Records retention schedule approved by legal counsel
- Secure disposal certificates from media destruction vendor
- Retention compliance audit evidence
- Statement of applicability lags behind risk assessment refresh
- Management review minutes record decisions without timed actions
- Retention schedule lags behind statutory minimums for some categories
- Disposal certificates retained inconsistently across vendors
Privacy
Per ISMS-P + PIPA: privacy management + Privacy Impact Assessment for Public Systems + align with Personal Information Protection Act (PIPA).
- KR ISMS-P evidence for KRISMSP-2
- KISA certification + PIPC partial
System and Operations Security
Implement system hardening standards for servers, databases, and network devices. Apply security patches within established timelines based on criticality.
- Baseline configuration documentation per system class
- Change advisory board records and approved RFCs
- Vulnerability scan reports and remediation tickets
- ISMS-P scope statement and statement of applicability
- Annual ISMS-P internal audit report
- Management review minutes with corrective actions
- Patch SLAs missed on legacy or unsupported platforms
- Baseline deviations accumulate without compensating controls
- Statement of applicability lags behind risk assessment refresh
- Management review minutes record decisions without timed actions
Implement encryption for personal information and important data at rest and in transit. Use approved cryptographic algorithms and proper key management.
- Cryptographic key management procedure and inventory
- Transport and at-rest encryption configuration evidence
- Algorithm and protocol approval register
- ISMS-P scope statement and statement of applicability
- Annual ISMS-P internal audit report
- Management review minutes with corrective actions
- Key rotation schedules documented but not enforced for legacy systems
- Cryptographic algorithm inventory incomplete or stale
- Statement of applicability lags behind risk assessment refresh
- Management review minutes record decisions without timed actions
Implement security monitoring including IDS/IPS, SIEM, and log analysis. Retain security logs for at least 1 year. Review logs regularly for anomalies.
- Centralised log aggregation configuration
- Log retention policy and archival evidence
- SIEM use-case catalogue and alert tuning history
- ISMS-P scope statement and statement of applicability
- Annual ISMS-P internal audit report
- Management review minutes with corrective actions
- Internal audit coverage skews to financial controls rather than full scope
- Log retention periods inconsistent across systems
- Statement of applicability lags behind risk assessment refresh
- Management review minutes record decisions without timed actions
Conduct regular vulnerability assessments and penetration testing. Remediate identified vulnerabilities based on severity and risk within defined timelines.
- Baseline configuration documentation per system class
- Change advisory board records and approved RFCs
- Vulnerability scan reports and remediation tickets
- ISMS-P scope statement and statement of applicability
- Annual ISMS-P internal audit report
- Management review minutes with corrective actions
- Patch SLAs missed on legacy or unsupported platforms
- Baseline deviations accumulate without compensating controls
- Statement of applicability lags behind risk assessment refresh
- Management review minutes record decisions without timed actions
Establish and maintain an incident response plan. Conduct regular incident response exercises. Report incidents to KISA within required timelines.
- Incident response plan with tested playbooks
- Incident tickets with timeline and root-cause analysis
- Breach notification templates and regulator submission logs
- ISMS-P scope statement and statement of applicability
- Annual ISMS-P internal audit report
- Management review minutes with corrective actions
- Notification timelines exceed statutory thresholds in practice
- Root-cause analysis not consistently completed for severity 2 incidents
- Statement of applicability lags behind risk assessment refresh
- Management review minutes record decisions without timed actions
Develop business continuity and disaster recovery plans. Conduct regular backups and test recovery procedures. Maintain alternate processing capabilities.
- ISMS-P scope statement and statement of applicability
- Annual ISMS-P internal audit report
- Management review minutes with corrective actions
- Statement of applicability lags behind risk assessment refresh
- Management review minutes record decisions without timed actions
- Documentation exists but lacks evidence of periodic refresh
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the South Korea ISMS-P framework page.