Tech for All > Security

Key Activities for Information Security

Information Security Governance Structure

  • Information Security Center
    • Information security oversight and governance across sites, business units, and overseas offices
    • Manages a global monitoring system for suspicious activities
  • Security Council
    • Discusses major security policies and protection measures
    • Shares and addresses current affairs, issues, and improvement plans
  • Information Security Department for Sites and Business Units
    • Manages security infrastructure, including access control and IT security for each site
    • Responds to security issues for each business unit
  • Regional Information Security Representatives
    • Establish policies aligned with local regulations and cultural considerations in each region
    • Addresses security issues within their assigned regions

Protecting Important Information Assets and Preventing Incidents

Samsung Electronics mitigates security vulnerabilities by security inspections of IT systems to secure our information assets and core tech. To secure Samsung Electronics' information assets and core technologies, we mitigate the vulnerabilities by regular security inspections of IT systems and operates security systems such as security monitoring of external hacker's attack, data encryption etc.

Operation of the Internal Reporting Process

Samsung Electronics operates a monthly security council(CISO Gyeong-heon Seo is the administrative secretary) to make decisions for important security policies, discuss security measures and performs the roles of security control tower.

Cyber Security and Data Protection Training

We operate a range of programs and provide company-wide online Data Protection Training to raise our employees’ awareness of the importance of cyber security and data protection.

We also conduct security trainings for engineers and other employees in charge of privacy-related tasks in individual business unit.

International Security Certifications

In addition to securing its information assets, Samsung Electronics develops and applies safe security features for each product and service. This enables us to provide a safe environment for customers using our products and services. We protect them from external data breaches and safely collect and store users’ personal information. Our management systems, products, and infrastructure solutions adhere to international security standards and undergo regular checks and certifications to ensure security.

Certifications received:
  • Korea Internet & Security Agency(KISA) Information Security Management System (ISMS) certification
  • ISO27001 (Information security management systems) certification - DS Division (Memory Business, Foundry Business, TSP), DX Division (Network Business, Mobile eXperience Business, Visual Display Business)
  • ISO27701 (International standard for privacy information management) certification
    - Visual Display Business, Global Marketing Office
  • Common Criteria (CC) certification - DS Division (System LSI Business, Foundry Business, TSP), DX Division(Visual Display Business, Samsung Research, Mobile eXperience Business)
  • Payment Card Industry Data Security Standard (PCI DSS) certification - DX Division (Mobile eXperience Business, Visual Display Business)
  • Service Organization Control (SOC) 2 certification - Mobile eXperience Business
  • Security Accreditation Scheme for UICC Production (SAS-UP) certification
    - System LSI Business
  • Korea Internet & Security Agency (KISA) IoT security certification - Digital Appliances Business (Bespoke Jet Bot Combo™ AI Steam robot vacuum cleaner)
  • Federal Information Processing Standards (FIPS) 140-3 Cryptographic Module Certification – Visual Display Business
Last updatedJune 27, 2025