ISMS-P 와 GDPR 의 개인정보보호 부문 연계 분석
A Linkage Analysis of ISMS-P and GDPR : Focused on Personal Information Protection
- 한국IT서비스학회
- 한국IT서비스학회지
- 한국IT서비스학회지 제18권 제2호
- : KCI등재
- 2019.06
- 55 - 73 (19 pages)
The importance of the personal information has been increased, there have been a lot of efforts to establish a new policy, certification or law for administrating personal information more effectively and safely. Korean government has operated ISMS and PIMS certification system to assess whether an organization has established and managed appropriate information security system or not. However, it has been addressed the needs for revising and modifying of PIMS and ISMS. It is evaluated there are a few overlapped criteria to assess information management system in both ISMS and PIMS. ISMS-P certification, combining with ISMS and PIMS, is, finally, suggested, in the recent. GDPR is established having an aim of primarily to give control to individuals over their personal data and to simplify the regulatory environment for international business by unifying the regulation within the EU. This study compares GDPR and ISMS-P, focusing on “personal information . It can be expected to contribute as followings. This study can be a criterion for self-evaluation of possibility to violate of GDPR of a firm in preparation for ISMS-P. Second, this study also aims to increase the understanding of the role of ISMS-P and GDPR, among various certifications with the purpose of assessment of the information security management system, by reducing the costs required to obtain the unnecessary certification and alleviating the burden. Third, it contributes to diffusion of ISMS-P newly implemented in Korea.
1. 서 론
2. 정보보호 및 개인정보보호 인증에 대한 선행 연구
3. ISMS-P 인증 및 GDPR
4. ISMS-P 인증과 GDPR 개인정보 보호 연계 분석