A Study on the Information Security Management Index through Analysis of EU-GDPR (European Union-General Data Protection Regulation)

  • Authors

    • Jin-Hwan Yoon
    • Yong-Tae Shin
    • Jong-Bae Kim
    https://doi.org/10.14419/ijet.v8i1.4.25462
  • EU-GDPR, Information Security Management System, Personal Information Management System, Privacy, ISMS. PIMS, Corporate Information Protection
  • The European Commission is committed to ensuring the free movement of personal information between EU Member States and strengthening the protection of the privacy of information by EU Member States through the EU General Regulations 2016/679 (General Data Protection Regulation: 'GDPR'), which entered into force on May 24, 2016, and  effect on May 25, 2018, and will have direct application and legal binding power to all EU Member States.

    Companies that are servicing the EU or preparing for business need to have a good understanding of the GDPR compliance requirements and need to comply with the relevant regulatory requirements.

    This study compares the legal core requirements between GDPR and domestic law, compares and analyzes the control items of ISMS (Information Security Management System & PIMS: Personal Information Management System) with the requirements of GDPR suggest ways to prepare a response system.

     

     

  • References

    1. [1] N. H Park etc 8, Editor, EU Privacy Protection Act 'GDPR', Park Young-su Publishers (2017)

      [2] EU Privacy Act (GDPR) analysis and privacy Legislative Improvement Legislation Demand Research, Korea University Industry-Academic Cooperation Foundation (2016)

      [3] Trends in GDPR responses of major overseas nations - mainly in EU member states, Korea Internet & Security Agency(2017), august. pp.220

      [4] The European Union's General Privacy Act 1st Guideline for Our Company, Korea Internet & Security Agency(2017)

      [5] ENISA. Handbook on Security of Personal Data Processing. Organizational and Technical Measures (2017), pp55-67

      [6] Trends in GDPR responses of major overseas nations - mainly in EU member states, Korea Internet & Security Agency(2017), august. pp.220

      [7] A Study on Coincidence Analysis of Domestic Information Security Management Indicator Against EU-GDPR, Soongsil University. (2018)

      [8] The Analysis of EU-GDPR(European Union-General Data Protection Regulation),

      [9] https://www.dlapiper.com/ko/korea/focus/eu-data-protection-regulation/background/, DAL PIPER(2018), Mar.

      [10] 2013 Research on the actual condition of the information security, Korea Internet & Security Agency(2013), Dec.

      [11] A handbook on ISMS certification system, Korea Internet & Security Agency(2013), Jun.

      [12] https://www.enisa.europa.eu/publications/recommendations-on-european-data-protection-certification/(2017), Nov 27

      [13] https://www.enisa.europa.eu/publications/handbook-on-security-of-personal-data-processing/(2018), Jan 29

      [14] http://imsm.kisa.or.kr, Korea Internet & Security Agency (2017)

      [15] European Commission, https://ec.europa.eu/info/law. (2018)

      [16] ENISA, https://www.enisa.europa.eu/publications/recommendations -on-europeandata-protection-certification/(2018),

      [17] ENISA, https://www.enisa.europa.eu/publications/handbook-on- security-of-personal-data-processing/, (2018) Jan 29

      [18] DAL PIPER, https://www.dlapiper.com/ko/korea/focus/eu-data- protection-regulation/background/. (2017)

      [19] Gemserv."GDPR-Finess-Guide"https://www.gemserv.com/ information-security/data-protection-gdpr/ (2017)

      [20] https://www.dlapiper.com/ko/korea/focus/eu-data-protection-regula tion/background/, DAL PIPER (2018)

      [21] MASON HAYES & CURRAN, Getting ready for the General Data Protection Regulation (2017) , pp 8

      [22] Current provisional indications of age of consent across the EU, Ingrida Milkaite and Eva Lievens, Ghent University (2018), Feb

  • Downloads

  • How to Cite

    Yoon, J.-H., Shin, Y.-T., & Kim, J.-B. (2019). A Study on the Information Security Management Index through Analysis of EU-GDPR (European Union-General Data Protection Regulation). International Journal of Engineering & Technology, 8(1.4), 507-517. https://doi.org/10.14419/ijet.v8i1.4.25462