Graphic = ChatGPT DALL·E

The review to renew LG Uplus' Information Security and Personal Information Protection Management System (ISMS-P) certification has been going on for more than a year. ISMS certification is mandatory for telecom carriers to operate their business. The previous certificate expired in Dec. 2025, but whether it will be renewed has not been decided yet.

The Korea Internet & Security Agency (KISA) said the review is underway but noted it is hard to disclose the reasons for the delay. In the industry, administrative probes and a police investigation into last year's alleged hacking of LG Uplus are seen as factors affecting the certification review.

◇ Renewal filed in July last year; review under way for more than a year

As of the 11th, according to the telecom industry, the validity period of LG Uplus' ISMS-P certificate was from Dec. 27, 2022, to Dec. 26, 2025. LG Uplus applied for renewal in July last year but has not yet been notified of the result. On the LG Uplus Personal Information Protection Center website, the expired certificate is still posted as the latest document.

ISMS is a system that assesses whether corporations have in place organizations and personnel to respond to hacking and data leaks, access control systems, and incident response procedures. ISMS-P adds a personal information protection domain that evaluates the entire process of collecting, using, providing, storing, and destroying personal data.

When corporations subject to mandatory ISMS, such as LG Uplus, obtain ISMS-P, they are deemed to have fulfilled the information security institutional sector certification requirement. KISA is in charge of the certification review, and the Ministry of Science and ICT and the Personal Information Protection Commission jointly oversee the system.

The industry cites the prolonged administrative probe and police investigation into hacking as the backdrop for the delayed renewal of LG Uplus' certification. After allegations surfaced last year that LG Uplus' internal server access control system (APPM) was hacked, leaking information from 8,938 servers and 42,256 account, the Personal Information Protection Commission launched an administrative investigation. The probe later expanded to a police investigation amid allegations that LG Uplus identified signs of hacking but failed to report them in time.

The security industry explains that because the items examined in the hacking investigation and in the ISMS-P certification review significantly overlap, it may be difficult to decide on certification before the probe's results are out. Jang Hang-bae, a professor in the Department of Industrial Security at Chung-Ang University, said, "Problems in the management system may surface during the hacking investigation; if certification is renewed before the results come out, the two judgments could conflict, which would also burden the certification body."

A KISA official said, "The review process is currently underway," but added, "It is difficult to answer the specific reasons for the delay."

◇ No immediate impact on services, but uncertainty in orders is a burden

Even if the certificate has expired, LG Uplus does not have to immediately suspend mobile services or terminate existing contracts. However, since some public institutions, financial institutions, and large corporations use ISMS or ISMS-P certification status as a bid condition or an evaluation item, a prolonged review could become a burden.

The currently disclosed certificate already shows the past validity period. As a result, LG Uplus may have to separately explain during bidding or during security evaluations by corporate customers that the renewal review is ongoing and clarify its current certification status. Of course, the mere fact that a renewal review is underway does not restrict participation in all projects. However, the longer the conclusion is delayed, the greater the uncertainty could grow in winning new contracts and renewing existing ones.

If LG Uplus ultimately fails to obtain the renewal and also does not secure a separate ISMS certification, it could face issues of violating the statutory certification obligation. Business operators who do not fulfill the ISMS certification obligation may be subject to fines of up to 30 million won, and it could become difficult to participate in new projects where holding certification is a mandatory condition.

The issue at hand is less the possibility of an immediate suspension of mobile services than the business uncertainty caused by a protracted review. With KISA not disclosing specific reasons for the delay, attention is on when and with what conclusion LG Uplus' certification review will be wrapped up.

※ This article has been translated by AI. Share your feedback here.