uniflow
KO / EN
Dev·개념·2026-09-28

ISMS vs ISMS-P in Korea — There Is No Such Thing as an "ISMS-P Obligation" (Yet)

Search results are full of the phrase 'ISMS-P obligation,' but Korean law mandates only ISMS. Here is how the two certifications split from one scheme, the structure of the 101 controls, why the confusion took hold, and why the phrase may become real in 2027.

🇰🇷 This article is about South Korean law. ISMS and ISMS-P here are the certification schemes under Korea's Act on Promotion of Information and Communications Network Utilization and Information Protection ("Network Act") — not ISO 27001 or any other country's framework. If you operate an online service in Korea, or your company is expanding into the Korean market, this distinction determines what you are legally required to do.

Search for "ISMS-P obligation" and you will find plenty of material — but the phrase does not exist in Korean law. What the Network Act mandates is ISMS (Information Security Management System) certification, full stop. ISMS-P is ISMS plus a personal-data track, and it is voluntary. Yet in practice the two names are used almost interchangeably, and that confusion leads companies to a badly framed question: "Are we required to get ISMS-P?" This article covers what the two certifications are, where they split, and why the mix-up took hold.

One scheme, two certifications

ISMS and ISMS-P are not separate regimes — they are two tracks of a single certification scheme. The current structure dates to 2018, when the Ministry of Science and ICT's ISMS and the Communications Commission's PIMS (Personal Information Management System) were merged to end the double burden on companies that had been certifying twice. The governing notification is now jointly issued by the Ministry of Science and ICT and the Personal Information Protection Commission.

ISMSISMS-P
Full nameInformation Security Management SystemPersonal Information & Information Security Management System
CoversSecurity of the information serviceSecurity + the flow of personal data
Controls80 items101 items (80 + 21 personal-data items)
Legally mandatoryYes — Network Act, Article 47(2)No — voluntary
Relationship—Obtaining ISMS-P satisfies the ISMS obligation

The last row is the key. ISMS-P contains ISMS. A company under the obligation that obtains ISMS-P has automatically met its legal duty. The reverse does not hold — a company holding only ISMS has not had its personal-data handling certified.

101 = 80 + 21 — the structure of the controls

The control structure makes the relationship visible:

  • 1. Management system establishment & operation — 16 items · policy, organization, assets, risk assessment, internal review. The skeleton of the management system
  • 2. Protection requirements — 64 items · personnel security, access control, encryption, secure development, backup, incident response
  • 3. Personal-data lifecycle requirements — 21 items · collection → retention → use and provision → destruction, plus data-subject rights

Areas 1 and 2 together (80 items) are ISMS; add area 3 and you have ISMS-P. The third area translates what Korea's Personal Information Protection Act demands — consent, retention periods, third-party provision, destruction, responding to access and deletion requests — into management-system language. Think of it as an audit of whether the promises in your privacy policy are actually kept.

Why the "ISMS-P obligation" confusion took hold

A phrase that does not exist in law became the de facto standard term for three reasons.

Advertisement본문 중간 · 반응형본 도메인에서만 게재

First, most obligated companies handle personal data. An online service crossing the KRW 10 billion revenue or one-million-user thresholds almost always has member data. If such a company obtains only ISMS, its personal-data handling stays outside the certificate — so certifying as ISMS-P from the start became the common practical choice. Since "the certification obligated companies actually get" was ISMS-P, the names blurred.

Second, the scheme has one name. Applications, audit agencies, and the governing notification all sit under the single "ISMS-P certification scheme" label. That the scheme's name and the scope of the legal obligation differ is something you only learn by reading the documents.

Third, the imprecision was mostly harmless — until it wasn't. Because ISMS-P contains ISMS, calling yourself an "ISMS-P obligated company" got the conclusion (you must certify) right anyway. The cost shows up in the other direction: companies assuming they are required to prepare to the 101-control standard when the law requires 80, and quotes and timelines scoped against the wrong number.

But in 2027, the phrase may become real

That is the current state — and a turning point has been announced. The certification reform plan published in April 2026 would make ISMS-P, not ISMS, mandatory for obligated companies from 2027. After repeated personal-data breach incidents, the direction is to close the structural gap where the mandatory certificate could leave personal data uncovered. The final notification still needs to be confirmed, but if the direction holds:

  • "ISMS-P obligation" goes from a phrase that is not in the law to one that is
  • Obligated companies currently preparing only to the ISMS standard (80 controls) will need the additional 21
  • Which is why, if you are starting certification now, building the management system to the 101-control standard from day one avoids doing the work twice

Whether your company is subject to the obligation at all can be checked with our ISMS obligation checker (Korean interface), and the schedule after designation — counted backward from the August 31 deadline — is covered in a separate article.

Summary

  • The legal obligation is ISMS only — Network Act, Article 47(2). "ISMS-P obligation" is not a phrase in current law
  • ISMS-P = ISMS (80 controls) + personal data (21) = 101. Obtaining ISMS-P automatically satisfies the ISMS obligation
  • The confusion stuck because most obligated companies handle personal data and certified as ISMS-P anyway
  • The 2027 reform plan would change the picture — ISMS-P mandatory for obligated companies. If you are starting now, build to the 101-control standard

References

Advertisement글 최하단 · 띠배너본 도메인에서만 게재