LG U+ CSIRT

RFC 2350 — LGUPLUS-CSIRT

RFC 2350 Description for the LG Uplus Computer Security Incident Response Team

Version 1.0 Last Updated 2026-09-22 Public
Reporting an Incident

If you have discovered a security vulnerability or a security incident related to LG Uplus services, please report it to isoc@lguplus.com. Sensitive information should be encrypted using the PGP public key provided below.

RFC 2350 Document (PDF) PGP Public Key (.asc) security.txt

1. Document Information

This document contains a description of LGUPLUS-CSIRT in accordance with RFC 2350. It provides basic information about the team, its channels of communication, and its roles and responsibilities.

1.1 Date of Last Update

Version 1.0 (2026-09-22)

1.2 Distribution List for Notifications

There is no distribution list for notifications. Any changes to this document are published on this public website.

1.3 Locations where this Document May Be Found

The current version of this document can be found at the address below.

https://csirt.lguplus.com/

PDF version: https://csirt.lguplus.com/rfc2350.pdf

1.4 Authenticating this Document

This document has been signed with the PGP key of LGUPLUS-CSIRT. Refer to section 2.8 for more details.

1.5 Document Identification

TitleRFC 2350 LGUPLUS-CSIRT
Version1.0
Document DateSeptember 2026
ExpirationThis document is valid until superseded by a later version

2. Contact Information

2.1 Name of the Team

Full nameLG Uplus Computer Security Incident Response Team
Short nameLGUPLUS-CSIRT

2.2 Address

LG Uplus Corp.
71, Magokjungang 8-ro, Gangseo-gu
Seoul, Republic of Korea

2.3 Time Zone

UTC+0900 (Asia/Seoul, KST)

2.4 Telephone Number

General+82-01-2233-0403

Note: Incident reports should be submitted by electronic mail.

2.5 Facsimile Number

None

2.6 Electronic Mail Address

All incident reports should be sent to the address below.

isoc@lguplus.com

2.7 Other Telecommunication

None

2.8 Public Keys and Encryption Information

Key ID0x00000000
Fingerprint0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
Downloadpgp-key.asc

Please use this public key to encrypt any communication containing sensitive information.

2.9 Team Members

LGUPLUS-CSIRT is made up of information security professionals belonging to the Information Security Incident Response Team of LG Uplus. An individual list of team members is not disclosed publicly.

2.10 Other Information

None

2.11 Points of Customer Contact

Reporting channelisoc@lguplus.com
Hours of operation09:00 – 18:00 (KST), Monday to Friday
Security monitoring24 hours a day, 7 days a week

Reports received outside of business hours are handled on the next business day. Urgent matters are addressed at any time through the 24/7 Security Operations Center.

3. Charter

3.1 Mission Statement

The mission of LGUPLUS-CSIRT is to protect the information and communications services provided by LG Uplus, as well as its internal information assets, against cyber threats, and to respond promptly to security incidents in order to minimise damage.

  • 24/7 monitoring and early detection of cyber threats
  • Rapid analysis, response and recovery support in the event of an incident
  • Incident prevention through proactive identification and remediation of vulnerabilities
  • Co-operation with domestic and international organisations and the security community

3.2 Constituency

The constituency of LGUPLUS-CSIRT consists of the information assets owned or operated by LG Uplus and the services delivered on the basis of those assets.

  • Domains and network assets owned by LG Uplus
  • Cloud environments and infrastructure operated by LG Uplus
  • Customer-facing services and internal business systems provided by LG Uplus

3.3 Sponsorship and/or Affiliation

LGUPLUS-CSIRT is organised under the information security function of LG Uplus and is funded internally by the company.

3.4 Authority

LGUPLUS-CSIRT is authorised to conduct investigation, analysis and response activities for security incidents within its constituency, on the basis of the internal information protection policies of LG Uplus and applicable legislation.

4. Policies

4.1 Types of Incidents and Level of Support

LGUPLUS-CSIRT addresses all types of information security incidents which occur, or threaten to occur, within its constituency. The level of support given will vary depending on the type and severity of the incident, the scope of impact, the importance of the affected assets and the resources available at the time.

Priority is determined based on the following factors.

  • Attack level — attack method, accessibility of the target, resulting impact
  • Damage status — scale of damage and likelihood of propagation
  • Functional impact — current and likely future impact on services and business functions
  • Asset importance — criticality of the affected assets
  • Recoverability — time and resources required for recovery

4.2 Co-operation, Interaction and Disclosure of Information

LGUPLUS-CSIRT co-operates with relevant domestic organisations and the security community in order to prevent and respond to security incidents.

All information processed by LGUPLUS-CSIRT is handled in accordance with internal information classification policy. Personal data and customer information are protected in accordance with applicable legislation. Where it becomes necessary to share information with third parties, the consent of the information owner is obtained beforehand.

4.3 Communication and Authentication

For information classified as public, LGUPLUS-CSIRT uses conventional methods such as unencrypted electronic mail. To ensure the security of communication involving sensitive information, PGP-encrypted electronic mail or telephone will be used.

5. Services

5.1 Incident Response

Incident Triage

  • Investigating whether an incident has indeed occurred
  • Determining the extent and impact of the incident

Incident Coordination

  • Determining the initial cause of the incident and the vulnerability exploited
  • Facilitating contact with other internal departments and external parties involved
  • Facilitating contact with appropriate authorities and law enforcement, if necessary
  • Composing announcements to users, where applicable

Incident Resolution

  • Incident analysis — evidence collection, tracking and tracing
  • On-site response and recommendations for securing affected systems
  • Vulnerability analysis and recommendations for remediation

5.2 Proactive Activities

  • Announcements including threat information, vulnerability warnings and security advisories
  • Intrusion detection and 24/7 security monitoring
  • Technology watch and analysis of security trends
  • Security audits and vulnerability assessments
  • Security awareness activities for employees

6. Incident Reporting Forms

There is no specific form for reporting incidents. Please send your report to isoc@lguplus.com including the information below.

  • Reporter information — name, organisation and contact details
  • Date and time of the incident, including the time zone
  • Affected systems — domains, IP addresses or service names
  • Description of the incident and observed symptoms
  • Supporting evidence such as relevant logs or screenshots
  • Any actions already taken

If your report contains sensitive information, please encrypt it using the PGP public key.

7. Disclaimers

While every precaution will be taken in the preparation of information, notifications and alerts, LGUPLUS-CSIRT assumes no responsibility for errors or omissions, or for damages resulting from the use of the information contained within.