바로가기 메뉴
본문 바로가기

Privacy

Privacy


SK gas management has a deep understanding of the importance of information protection and customer information protection. As such, an executive and an organization in charge are appointed, and the organization in charge cooperates with internal related organizations or obtains cooperation from external organizations to conduct activities and efforts to protect customer information

[Organization in charge of information protection and personal information protection ]

  • Legal/compliance

    • Monitor related laws and trends
    • Manage and review compliance and risk hedging

    SK group security manager

    • Share company trends, security trends, accident cases, etc
    • Diagnose/inspect security status
    • Create/distribute general guide to improve security
  • Information Protection Organization (IT strategy support office)

    • Establish and operate information protection strategy/process
      • Reflect relevant laws and trends into regulation/policy and continue improvement
    • Conduct awareness activities and manage changes through staff training and mock training
    • Establish IT security policy, establish and operate security system
  • Officer in charge of personal information protection by business

    • Execute responsible customer information protection policy by designating a personal information protection manager and officer in charge in the organization in charge of each business/customer
      • Customer information collection consent/storage/disposal and procedure/process definition
      • Conduct regular checks and improvement activities
      • Respond to customer information leakage incidents
  • [External] Government agencies/organizations

    • CISO designation report completed (Ministry of Science and ICT, March 2020)
    • Share security incidents and trend information
    • Receive and inspect security guide for national security facility management

Main activities and plans for information protection and personal information protection in 2021

Policy

  • 1. Inspect and establish information security management system

    • Utilize external experts to check the status of all areas of information protection, including security management system, system security, and physical security, and establish improvement tasks
    • Establish and supplement information security management system
  • 2. Promote enactment/revision of information protection related regulations and guidelines

Goal

  • 1. Establish mid/long-term master plan for information protection

    • Establish mid/long-term master plan and implementation plan
    • Review acquisition of external certification for corporate data/personal information protection management system (ISMS-P)
  • 2. Maintain 0 confidentiality/personal information leakage accidents

Implementation/performance management

  • 1. Information protection education for all employees, personal information protection education for personal information manager/person in charge
  • 2. Efforts to prevent confidentiality leakage through regular security checks and activities to increase awareness among members
  • 3. Distribute/train security guides for developers/administrators
  • 4. Improve vulnerabilities before opening through new/reformed system vulnerability check and mock hacking
  • 5. Reorganize personal information protection system and establish security system according to the establishment of the happy charging membership system

    • Enact/amend personal information processing policy, strengthen and inspect security for personal information handlers