Skip to content

Evidence request lists

South Korea ISMS-P

Evidence request list. 25 controls, 25 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Access Control

ISMSP-AC-01
Access Control Policy

Establish access control policies based on the principle of least privilege. Implement formal authorization procedures for system and information access.

Artefacts an auditor will ask for
  • Approved governance policy with documented scope and accountabilities
  • Board or steering committee minutes evidencing oversight
  • Roles and responsibilities matrix (RACI)
  • Access provisioning and review records
  • Multi-factor authentication configuration evidence
  • Privileged access management logs
Where this commonly fails
  • Policy document exists but lacks evidence of board approval or refresh cycle
  • Accountabilities defined on paper but not reflected in performance objectives
  • Privileged accounts not subject to regular re-certification
  • Multi-factor authentication not enforced for all in-scope systems
  • Statement of applicability lags behind risk assessment refresh
ISMSP-AC-02
User Account Management

Manage user accounts throughout their lifecycle including creation, modification, periodic review, and deactivation. Implement unique identification for all users.

Artefacts an auditor will ask for
  • Access provisioning and review records
  • Multi-factor authentication configuration evidence
  • Privileged access management logs
  • ISMS-P scope statement and statement of applicability
  • Annual ISMS-P internal audit report
  • Management review minutes with corrective actions
Where this commonly fails
  • Privileged accounts not subject to regular re-certification
  • Multi-factor authentication not enforced for all in-scope systems
  • Statement of applicability lags behind risk assessment refresh
  • Management review minutes record decisions without timed actions
ISMSP-AC-03
Authentication Mechanisms

Implement strong authentication mechanisms including password policies, multi-factor authentication for sensitive systems, and session management controls.

Artefacts an auditor will ask for
  • Access provisioning and review records
  • Multi-factor authentication configuration evidence
  • Privileged access management logs
  • ISMS-P scope statement and statement of applicability
  • Annual ISMS-P internal audit report
  • Management review minutes with corrective actions
Where this commonly fails
  • Privileged accounts not subject to regular re-certification
  • Multi-factor authentication not enforced for all in-scope systems
  • Statement of applicability lags behind risk assessment refresh
  • Management review minutes record decisions without timed actions
ISMSP-AC-04
Network Access Control

Control network access through segmentation, firewall policies, VPN for remote access, and network monitoring. Restrict unauthorized network connections.

Artefacts an auditor will ask for
  • Access provisioning and review records
  • Multi-factor authentication configuration evidence
  • Privileged access management logs
  • ISMS-P scope statement and statement of applicability
  • Annual ISMS-P internal audit report
  • Management review minutes with corrective actions
Where this commonly fails
  • Privileged accounts not subject to regular re-certification
  • Multi-factor authentication not enforced for all in-scope systems
  • Statement of applicability lags behind risk assessment refresh
  • Management review minutes record decisions without timed actions
  • East-west traffic monitoring weaker than perimeter monitoring
KRISMSP-3
Access Control, Cryptography, Logging

Per ISMS-P: access control + cryptography + logging + audit + Korean specific encryption (SEED + ARIA).

Artefacts an auditor will ask for
  • KR ISMS-P evidence for KRISMSP-3
Where this commonly fails
  • KISA certification + PIPC partial

Certification

KRISMSP-5
KISA + PIPC Cooperation, Certification, Recertification

Per ISMS-P: KISA certification + PIPC cooperation + 3-year recertification + maintenance reviews.

Artefacts an auditor will ask for
  • KR ISMS-P evidence for KRISMSP-5
Where this commonly fails
  • KISA certification + PIPC partial

ISMS

KRISMSP-1
Information Security Management System

Per South Korea ISMS-P (KISA): ISMS. Requirements include (a) Information Security and Privacy Management System + (b) Chief Information Security Officer Designation + (c) Information Asset Inventory and Classification + (d) Risk Assessment and Treatment + (e) KISA certification.

Artefacts an auditor will ask for
  • KR ISMS-P evidence for KRISMSP-1
Where this commonly fails
  • KISA certification + PIPC partial

Incident Response

KRISMSP-4
Incident Response and Breach Notification

Per ISMS-P + PIPA: incident response + breach notification to PIPC + KISA + affected subjects.

Artefacts an auditor will ask for
  • KR ISMS-P evidence for KRISMSP-4
Where this commonly fails
  • KISA certification + PIPC partial

Management System

ISMSP-MS-01
Information Security Policy and Organization

Establish an information security policy approved by top management. Designate a CISO and establish an information security organization with clear roles and responsibilities.

Artefacts an auditor will ask for
  • Approved governance policy with documented scope and accountabilities
  • Board or steering committee minutes evidencing oversight
  • Roles and responsibilities matrix (RACI)
  • ISMS-P scope statement and statement of applicability
  • Annual ISMS-P internal audit report
  • Management review minutes with corrective actions
Where this commonly fails
  • Policy document exists but lacks evidence of board approval or refresh cycle
  • Accountabilities defined on paper but not reflected in performance objectives
  • Statement of applicability lags behind risk assessment refresh
  • Management review minutes record decisions without timed actions
ISMSP-MS-02
Risk Management

Establish and implement a risk management process including asset identification, threat and vulnerability assessment, risk analysis, and risk treatment plan development.

Artefacts an auditor will ask for
  • Risk register with treatment plans and owner sign-offs
  • Risk appetite statement approved by the board
  • Periodic risk review reports
  • ISMS-P scope statement and statement of applicability
  • Annual ISMS-P internal audit report
  • Management review minutes with corrective actions
Where this commonly fails
  • Statement of applicability lags behind risk assessment refresh
  • Management review minutes record decisions without timed actions
  • Documentation exists but lacks evidence of periodic refresh
ISMSP-MS-03
Information Security Plan

Develop annual information security plans including objectives, resource allocation, implementation schedule, and performance metrics. Obtain top management approval.

Artefacts an auditor will ask for
  • ISMS-P scope statement and statement of applicability
  • Annual ISMS-P internal audit report
  • Management review minutes with corrective actions
Where this commonly fails
  • Statement of applicability lags behind risk assessment refresh
  • Management review minutes record decisions without timed actions
  • Documentation exists but lacks evidence of periodic refresh
ISMSP-MS-04
Management Review and Improvement

Conduct periodic management reviews of the information security management system. Monitor performance metrics and implement continuous improvement measures.

Artefacts an auditor will ask for
  • ISMS-P scope statement and statement of applicability
  • Annual ISMS-P internal audit report
  • Management review minutes with corrective actions
  • Post-incident review template completed for each major incident
  • Improvement backlog with prioritisation and closure evidence
  • Annual programme effectiveness review
Where this commonly fails
  • Statement of applicability lags behind risk assessment refresh
  • Management review minutes record decisions without timed actions
  • Improvement actions raised but closure evidence lacking
  • Trend analysis across incidents not consistently performed

Personal Information Protection

ISMSP-PI-01
Personal Information Collection

Collect personal information only with the data subject's consent for specified purposes. Collect minimum information necessary. Provide clear privacy notices.

Artefacts an auditor will ask for
  • ISMS-P scope statement and statement of applicability
  • Annual ISMS-P internal audit report
  • Management review minutes with corrective actions
Where this commonly fails
  • Statement of applicability lags behind risk assessment refresh
  • Management review minutes record decisions without timed actions
  • Documentation exists but lacks evidence of periodic refresh
ISMSP-PI-02
Purpose Limitation and Use

Use personal information only for the specified purpose of collection. Secondary use requires additional consent or legal basis. Maintain records of processing activities.

Artefacts an auditor will ask for
  • Records of processing activities (Article 30 style register)
  • Lawful basis assessment per processing purpose
  • Data minimisation review evidence
  • ISMS-P scope statement and statement of applicability
  • Annual ISMS-P internal audit report
  • Management review minutes with corrective actions
Where this commonly fails
  • Records of processing activities outdated against current systems
  • Lawful basis selections rely on consent where alternative is more defensible
  • Statement of applicability lags behind risk assessment refresh
  • Management review minutes record decisions without timed actions
ISMSP-PI-03
Third-Party Provision and Outsourcing

Obtaining consent before providing personal information to third parties. When outsourcing processing, manage and supervise the outsourcee's handling of personal information.

Artefacts an auditor will ask for
  • Third-party risk assessment dossier per vendor
  • Signed contracts with required protection clauses
  • Ongoing assurance reports (SOC 2, ISO, audit findings)
  • ISMS-P scope statement and statement of applicability
  • Annual ISMS-P internal audit report
  • Management review minutes with corrective actions
Where this commonly fails
  • Vendor risk assessments not refreshed at the required cadence
  • Subcontractor flow-down clauses absent or weak in contracts
  • Statement of applicability lags behind risk assessment refresh
  • Management review minutes record decisions without timed actions
  • Concentration risk across critical suppliers not actively monitored
ISMSP-PI-04
Cross-Border Transfer

Inform data subjects and obtain consent before transferring personal information overseas. Ensure adequate protection measures at the receiving end.

Artefacts an auditor will ask for
  • Transfer impact assessment records
  • Standard contractual clauses and adequacy decision references
  • Transfer register with safeguards documented
  • ISMS-P scope statement and statement of applicability
  • Annual ISMS-P internal audit report
  • Management review minutes with corrective actions
Where this commonly fails
  • Transfer impact assessments missing for legacy data flows
  • Standard contractual clauses not aligned to the current EU template version
  • Statement of applicability lags behind risk assessment refresh
  • Management review minutes record decisions without timed actions
ISMSP-PI-05
Data Subject Rights

Ensure data subjects can exercise their rights including access, correction, deletion, suspension of processing, and withdrawal of consent. Respond within legal timelines.

Artefacts an auditor will ask for
  • Consent capture records with timestamps and scope
  • Data subject request log with response evidence
  • Privacy notice versions with change history
  • ISMS-P scope statement and statement of applicability
  • Annual ISMS-P internal audit report
  • Management review minutes with corrective actions
Where this commonly fails
  • Consent capture mechanisms do not record granularity required by law
  • Data subject request workflow exceeds statutory response deadlines
  • Statement of applicability lags behind risk assessment refresh
  • Management review minutes record decisions without timed actions
ISMSP-PI-06
Personal Information Destruction

Destroy personal information without delay when retention period expires or purpose is achieved. Use methods that prevent recovery: physical destruction, overwriting, or degaussing.

Artefacts an auditor will ask for
  • ISMS-P scope statement and statement of applicability
  • Annual ISMS-P internal audit report
  • Management review minutes with corrective actions
  • Records retention schedule approved by legal counsel
  • Secure disposal certificates from media destruction vendor
  • Retention compliance audit evidence
Where this commonly fails
  • Statement of applicability lags behind risk assessment refresh
  • Management review minutes record decisions without timed actions
  • Retention schedule lags behind statutory minimums for some categories
  • Disposal certificates retained inconsistently across vendors

Privacy

KRISMSP-2
Privacy Management System and PIA

Per ISMS-P + PIPA: privacy management + Privacy Impact Assessment for Public Systems + align with Personal Information Protection Act (PIPA).

Artefacts an auditor will ask for
  • KR ISMS-P evidence for KRISMSP-2
Where this commonly fails
  • KISA certification + PIPC partial

System and Operations Security

ISMSP-SYS-01
System Hardening and Patch Management

Implement system hardening standards for servers, databases, and network devices. Apply security patches within established timelines based on criticality.

Artefacts an auditor will ask for
  • Baseline configuration documentation per system class
  • Change advisory board records and approved RFCs
  • Vulnerability scan reports and remediation tickets
  • ISMS-P scope statement and statement of applicability
  • Annual ISMS-P internal audit report
  • Management review minutes with corrective actions
Where this commonly fails
  • Patch SLAs missed on legacy or unsupported platforms
  • Baseline deviations accumulate without compensating controls
  • Statement of applicability lags behind risk assessment refresh
  • Management review minutes record decisions without timed actions
ISMSP-SYS-02
Encryption Implementation

Implement encryption for personal information and important data at rest and in transit. Use approved cryptographic algorithms and proper key management.

Artefacts an auditor will ask for
  • Cryptographic key management procedure and inventory
  • Transport and at-rest encryption configuration evidence
  • Algorithm and protocol approval register
  • ISMS-P scope statement and statement of applicability
  • Annual ISMS-P internal audit report
  • Management review minutes with corrective actions
Where this commonly fails
  • Key rotation schedules documented but not enforced for legacy systems
  • Cryptographic algorithm inventory incomplete or stale
  • Statement of applicability lags behind risk assessment refresh
  • Management review minutes record decisions without timed actions
ISMSP-SYS-03
Security Monitoring and Log Management

Implement security monitoring including IDS/IPS, SIEM, and log analysis. Retain security logs for at least 1 year. Review logs regularly for anomalies.

Artefacts an auditor will ask for
  • Centralised log aggregation configuration
  • Log retention policy and archival evidence
  • SIEM use-case catalogue and alert tuning history
  • ISMS-P scope statement and statement of applicability
  • Annual ISMS-P internal audit report
  • Management review minutes with corrective actions
Where this commonly fails
  • Internal audit coverage skews to financial controls rather than full scope
  • Log retention periods inconsistent across systems
  • Statement of applicability lags behind risk assessment refresh
  • Management review minutes record decisions without timed actions
ISMSP-SYS-04
Vulnerability Management

Conduct regular vulnerability assessments and penetration testing. Remediate identified vulnerabilities based on severity and risk within defined timelines.

Artefacts an auditor will ask for
  • Baseline configuration documentation per system class
  • Change advisory board records and approved RFCs
  • Vulnerability scan reports and remediation tickets
  • ISMS-P scope statement and statement of applicability
  • Annual ISMS-P internal audit report
  • Management review minutes with corrective actions
Where this commonly fails
  • Patch SLAs missed on legacy or unsupported platforms
  • Baseline deviations accumulate without compensating controls
  • Statement of applicability lags behind risk assessment refresh
  • Management review minutes record decisions without timed actions
ISMSP-SYS-05
Incident Response

Establish and maintain an incident response plan. Conduct regular incident response exercises. Report incidents to KISA within required timelines.

Artefacts an auditor will ask for
  • Incident response plan with tested playbooks
  • Incident tickets with timeline and root-cause analysis
  • Breach notification templates and regulator submission logs
  • ISMS-P scope statement and statement of applicability
  • Annual ISMS-P internal audit report
  • Management review minutes with corrective actions
Where this commonly fails
  • Notification timelines exceed statutory thresholds in practice
  • Root-cause analysis not consistently completed for severity 2 incidents
  • Statement of applicability lags behind risk assessment refresh
  • Management review minutes record decisions without timed actions
ISMSP-SYS-06
Business Continuity and Disaster Recovery

Develop business continuity and disaster recovery plans. Conduct regular backups and test recovery procedures. Maintain alternate processing capabilities.

Artefacts an auditor will ask for
  • ISMS-P scope statement and statement of applicability
  • Annual ISMS-P internal audit report
  • Management review minutes with corrective actions
Where this commonly fails
  • Statement of applicability lags behind risk assessment refresh
  • Management review minutes record decisions without timed actions
  • Documentation exists but lacks evidence of periodic refresh
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the South Korea ISMS-P framework page.