original hero image


Information Protection and Security Framework


Information Security Policy

SK ecoplant has established information security policies, including information security regulations and personal data management regulations, to safely protect the information assets of both the company and its customers. The information security regulations include detailed rules for each area, such as the “Personnel Security Standards” and “Security Audit Standards.” Under each of these rules, guidelines, manuals, and other documents have been prepared to provide specific standards for performing work tasks. In addition, to protect corporate confidentiality and customer personal data, the company operates a 24-hour monitoring system and controls access to critical data in accordance with the three principles of access control: “Need to Know,” “Least Privilege Policy,” and “Separation of Duties.”

Information security policies are periodically established and revised to reflect relevant laws and regulations as well as technological and industry trends. SK ecoplant verifies policy compliance and the adequacy of protective measures through regular security assessments, inspections, and audits. Based on this, the security management system is being continually enhanced across administrative, physical, and technical aspects. In 2025, the company revised its security regulations and personal data management regulations to clarify the composition and roles of the Information Protection Committee and Information Protection Working Council, while amending the “Physical Security Standards” to strengthen requirements for wearing physical access cards (employee ID cards). Furthermore, SK ecoplant revised the “Security System Security Guidelines” to explicitly specify the minimum retention period for security system audit logs, thereby clarifying compliance standards with relevant laws and regulations.

Information Security Certification

To strengthen the stability and reliability of its information security framework, SK ecoplant has obtained and maintains domestic and international information security certifications. To ensure a secure management system for personally identifiable information (PII), the company maintains not only ISO 27001 (Information Security Management Systems) and ISO 27701 (Privacy Information Management Systems) certifications but also the Personal information & Information Security Management System (ISMS-P) certification. In 2025, following the addition of new personal data processing systems, the company underwent an initial ISMS-P audit and expansion audits for ISO 27001 as well as ISO 27701 certifications to verify the level of administrative and technical protective measures for the new systems. Moving forward, SK ecoplant plans to continue verifying the adequacy of its management system through follow-up audits.

Status of Information Security Certifications

Category

ISO 27001

ISO 27701

ISMS-P

Standard

International

International

Domestic

Validity Period

Sep. 28, 2024 – Sep. 27, 2027

Sep. 28, 2024 – Sep. 27, 2027

Jan. 21, 2026 – Jan. 20, 2029

Certification
Scope

Pre-sale, occupancy, defect repair, and customer support (inquiries) services

Certification
Impact

  • Compliance with global client requirements and enhanced credibility

  • Adherence to domestic and international information security regulations

  • Objective verification of information security levels when participating in domestic and international projects

  • Business stability secured through systematic management of information security risks


Information Security Governance

SK ecoplant’s information protection and security organization consists of experts in information security, personal data protection, and information and communications technology, each with an average of over 17 years of experience. The organization establishes company-wide security objectives, operates an integrated information protection framework, and conducts continuous monitoring to prevent security incidents. Additionally, it assesses, inspects, and audits policy compliance within organizations responsible for security operations and execution, and responds swiftly to security incidents to prevent further damage.

The Information Protection Council, the highest decision-making body for information protection and security, is chaired by the CISO (Chief Information Security Officer), the CPO (Chief Privacy Officer), and the Location Information Manager. Together with organizations that handle customer personal data and location data—such as IT, Pre-Sales, Customer Service, and Safety—the council discusses key decision-making matters, including the status and plans for security activities in each department. In 2025, a total of four council meetings were held to discuss compliance measures related to the Act on Promotion of Information and Communications Network Utilization and Information Protection, Personal Information Protection Act, and Act on the Protection and Use of Location Information, as well as the results of implementing internal personal data management plans and the outcomes of effectiveness assessments. Starting in 2026, operations will be separated into the Information Protection Committee—a decision-making body composed of senior management—and the Information Protection Working Council, consisting of leaders and members from operational units.

The Chief Information Security Officer (CISO), Chief Privacy Officer (CPO), and Location Information Manager are responsible for directing and supervising all information security and security operations. When appointing these officers, SK ecoplant establishes and adheres to internal standards that reflect the qualification requirements stipulated in relevant laws—such as the Act on Promotion of Information and Communications Network Utilization and Information Protection, Personal Information Protection Act, and Act on the Protection and Use of Location Information—to ensure that their activities are based on professional expertise. Currently, SK ecoplant’s information protection and security officers are experts with over 13 years of experience in their respective fields, exceeding the legal qualification requirements.


Information Security Organizational Chart



Roles and Responsibilities of Information Security Officers

Category

Roles and Responsibilities

Chief Information Security Officer
(CISO)

  • Establishment, implementation, and improvement of the information security plan

  • Regular audits and improvements of information security practices and conditions

  • Identification and assessment of information security risks and development of countermeasures

  • Planning and implementation of information security training programs and simulation exercises

Chief Privacy Officer (CPO)

  • Establishment and implementation of a personal information protection plan

  • Regular reviews and improvements of personal data processing practices and conditions

  • Handling of complaints and remedies related to personal data processing

  • Establishment of an internal control system to prevent leakage, misuse, or abuse of personal data

  • Planning and implementation of personal data protection training programs

  • Protection, management, and supervision of personal data files

Location Information Manager

  • Overall management of location data collection, use, provision, disposal, and control

  • Inspection of illegal or improper acts involving location data by employees of location-based service providers or third parties

  • Handling and oversight of complaints and concerns raised by individuals regarding location data

Information Security Objectives

SK ecoplant is proactively mitigating information security risks with the goal of achieving “Zero incidents of data breaches and violations of relevant regulations.” To this end, the company has broken down its information security activities into seven areas: personal data management, internal information leakage control, cyber threat response, location information management, cloud security, AI security, and subsidiary security management support. For each area, it has established and is managing mid- to long-term roadmaps to advance information security based on AI and the Zero Trust security model*.

* Zero-Trust security model: A network security model that assumes all internet environments are potentially vulnerable to intrusion and strengthens monitoring, authentication, and access control


Roadmap for Information Security Initiatives

Category

2026

2027

2028

Personal Data
Management

  • Enhancement of personal data handler conduct inspection systems (customers)

  • Enhancement of personal data handler conduct inspection systems (employees, external)

  • Regular implementation and improvement of internal personal data status audits

Internal Information
Leakage Control

  • Next-generation document security and integrated PC security solution

  • Advancement of AI-based internal information leak detection systems

  • Automation of AI-based internal information leak detection systems

Cyber Threat
Response

  • Advancement of Security Information and Event Management (SIEM) platform

  • IT infrastructure security patch management

  • Establishing a protection system applying Micro-Segmentation

  • Implementing automated AI mock hacking solutions

Location Information Management

  • Conducting regular internal location information audits and implementing improvements

  • Conducting regular internal location information audits and implementing improvements

  • Conducting regular internal location information audits and implementing improvements

Cloud Security

  • Continuous monitoring of CSPM and managing cloud security levels

  • Continuous monitoring of CSPM and managing cloud security levels

  • Continuous monitoring of CSPM and managing cloud security levels

AI Security

  • Establishing AI security guidelines and utilization standards

  • AI-based security threat detection

  • Establishment of an AI-based autonomous response system

Subsidiary Security
Management Support

  • Provision of security services tailored to each subsidiary’s management environment

  • Provision of security services tailored to each subsidiary’s management environment

  • Achieve Level 3.0(Good) or higher in the Group’s security management system

Information Security Framework


Information Protection and Security Activities


Information Security Risk Management


Personal Data Management

SK ecoplant has obtained domestic and international certifications related to information security and the protection of customer personal data, including ISO 27001, ISO 27701, and ISMS-P, and operates a management system based on these certifications to safely protect customers’ valuable information assets. To improve stakeholders’ access to information regarding personal data management, a user-friendly version of the Privacy Policy has been posted to the company website. The company has also incorporated amendments to the Personal Information Protection Act into internal management plans and conducted inspections as well as improvements to further strengthen personal data protection standards. In 2025, SK ecoplant strengthened the management of personal data processing for subsidiary employees and external parties*, and conducted internal audits and improvement activities covering all personal data of customers, employees, and external parties. In 2026, the company plans to continue strengthening security systems to ensure that the personal data of employees and external parties is managed as securely as that of customers.

* External parties: Non-employees who work at or have access to SK ecoplant’s offices and sites, or who have authorization to access the company’s systems


Internal Information Leakage Control

SK ecoplant constantly detects abnormal attempts and signs of internal information leaks through its anomaly monitoring system. By optimizing internal information leakage monitoring scenarios, false positives and negatives have been reduced, while monitoring accuracy has been enhanced. Additionally, measures are being implemented to reduce the risk of external document leaks to raise employees’ security awareness. In 2025, SK ecoplant established a security model for 3D design drawings at semiconductor sites, and plans to build an information leakage monitoring system for these sites in 2026.


Cyber Threat Response

SK ecoplant operates a multi-layered security system and professional security monitoring 24/7 to respond to cybersecurity threats. These measures block hacking and intrusion attempts targeting IT infrastructure and information systems, while comprehensive assessments of information leakage risks are conducted and used as foundational data to advance the risk response framework. To detect security threats in real time, the company monitors monitor the dark web, ASM (Attack Surface Management)*, EDR (Endpoint Detection & Response)**, and Active Directory (AD) security solutions. Additionally, it proactively identifies and addresses hidden security risks through penetration testing conducted by white-hat hackers. In 2026, SK ecoplant plans to enhance the stability of real-time monitoring by upgrading its aging security monitoring platform and strengthen real-world response capabilities through cyber simulation exercises involving senior management.

* ASM (Attack Surface Management): A security approach that continuously discovers and manages all externally exposed assets, such as servers, domains, IP addresses, and cloud resources ** EDR (Endpoint Detection & Response): A security system that detects and responds to threats originating from PCs, servers, and other devices in real time


Location Information Management

SK ecoplant protects customers’ location information in compliance with relevant laws and regulations. In particular, to enhance the security of customer location information, the company has established and is implementing an internal management plan that includes self-assessments of location information handling practices and related training. In 2025, the company further strengthened the security of personal location information by refining its location information protection guidelines and developing an inspection checklist that incorporates requirements for compliance with relevant laws and regulations. In 2026, SK ecoplant seeks to continue conducting internal audits of location information handling practices and pursuing improvement initiatives.

Cloud Security

When building new cloud-based IT systems, SK ecoplant conducts a pre-assessment of security measures and, after deployment, continuously monitors system security using a Cloud Security Posture Management (CSPM) solution to manage the overall security level of its cloud environment.


AI Security

In step with the proliferation of generative AI technology, SK ecoplant is establishing an AI security governance framework that balances productivity innovation with information protection. The company comprehensively reviews security controls to ensure AI is utilized primarily through approved services, while continuously evaluating the security and utility of new AI services through a whitelist management system (which allows only permitted items to pass while blocking all others).

In particular, SK ecoplant applies differentiated usage standards based on sensitivity levels for critical data, such as personal data and industrial technology data, and is strengthening post-implementation management system based on monitoring and user behavior analysis. Through the establishment of an AI security framework, employee training, and verification of generated results, the company is fostering a culture of responsible AI use, while also identifying and managing risks arising from the use of generative AI or external AI services without proper approval or control. Going forward, SK ecoplant seeks to proactively respond to environmental changes that pose threats to AI technology and security, further advancing the safety and reliability of its AI security framework.


Subsidiary Security Management Support

SK ecoplant is striving to establish a company-wide, advanced information security framework by providing tailored support to strengthen the information security capabilities of its subsidiaries. For subsidiaries with relatively limited control over cybersecurity threats, the company provides a “Security Shared Service” that leverages headquarters resources, such as training and inspections. CISO councils are held with subsidiaries in the first and second halves of the year to regularly share security support measures. Additionally, cyber simulation exercises are conducted to raise information security awareness among subsidiary employees and develop improvement plans that reflect IT system vulnerability assessments and security requirements for each subsidiary.

For newly acquired subsidiaries, SK ecoplant assesses their security levels in accordance with its security management system. Based on the results, assistance is provided to establish improvement goals, identify improvement tasks, and implement them. In addition, the company assists subsidiaries in setting medium- to long-term security goals tailored to their business environment and autonomously operating their information protection and security systems.


Subsidiary Security Management System

Investment in Information Security

SK ecoplant is investing in information security to strengthen its internal capabilities and respond to external security incidents. In 2025, information security investment accounted for approximately 7.2% of the total IT budget.


Information Security Education and Training

SK ecoplant conducts annual online information security training for all employees in addition to providing job-specific security training, such as secure coding and training for personnel handling personal data. To proactively respond to increasingly sophisticated cyber threats, the company also conducts various types of simulation exercises every year. To internalize cyber attack response capabilities, SK ecoplant conducts training that reflects real-world scenarios, such as DDoS attack response, system recovery, and encryption key changes. The company has also objectively assessed its security level through participation in two simulation exercises organized by the Korea Internet & Security Agency (KISA).