1. Document Information
This document contains a description of LGUPLUS-CSIRT in accordance with RFC 2350. It provides basic information about the team, its channels of communication, and its roles and responsibilities.
1.1 Date of Last Update
Version 1.0 (2026-09-22)
1.2 Distribution List for Notifications
There is no distribution list for notifications. Any changes to this document are published on this public website.
1.3 Locations where this Document May Be Found
The current version of this document can be found at the address below.
PDF version: https://csirt.lguplus.com/rfc2350.pdf
1.4 Authenticating this Document
This document has been signed with the PGP key of LGUPLUS-CSIRT. Refer to section 2.8 for more details.
1.5 Document Identification
| Title | RFC 2350 LGUPLUS-CSIRT |
|---|---|
| Version | 1.0 |
| Document Date | September 2026 |
| Expiration | This document is valid until superseded by a later version |
2. Contact Information
2.1 Name of the Team
| Full name | LG Uplus Computer Security Incident Response Team |
|---|---|
| Short name | LGUPLUS-CSIRT |
2.2 Address
LG Uplus Corp.
71, Magokjungang 8-ro, Gangseo-gu
Seoul, Republic of Korea
2.3 Time Zone
UTC+0900 (Asia/Seoul, KST)
2.4 Telephone Number
| General | +82-01-2233-0403 |
|---|
Note: Incident reports should be submitted by electronic mail.
2.5 Facsimile Number
None
2.6 Electronic Mail Address
All incident reports should be sent to the address below.
2.7 Other Telecommunication
None
2.8 Public Keys and Encryption Information
| Key ID | 0x00000000 |
|---|---|
| Fingerprint | 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 |
| Download | pgp-key.asc |
Please use this public key to encrypt any communication containing sensitive information.
2.9 Team Members
LGUPLUS-CSIRT is made up of information security professionals belonging to the Information Security Incident Response Team of LG Uplus. An individual list of team members is not disclosed publicly.
2.10 Other Information
None
2.11 Points of Customer Contact
| Reporting channel | isoc@lguplus.com |
|---|---|
| Hours of operation | 09:00 – 18:00 (KST), Monday to Friday |
| Security monitoring | 24 hours a day, 7 days a week |
Reports received outside of business hours are handled on the next business day. Urgent matters are addressed at any time through the 24/7 Security Operations Center.
3. Charter
3.1 Mission Statement
The mission of LGUPLUS-CSIRT is to protect the information and communications services provided by LG Uplus, as well as its internal information assets, against cyber threats, and to respond promptly to security incidents in order to minimise damage.
- 24/7 monitoring and early detection of cyber threats
- Rapid analysis, response and recovery support in the event of an incident
- Incident prevention through proactive identification and remediation of vulnerabilities
- Co-operation with domestic and international organisations and the security community
3.2 Constituency
The constituency of LGUPLUS-CSIRT consists of the information assets owned or operated by LG Uplus and the services delivered on the basis of those assets.
- Domains and network assets owned by LG Uplus
- Cloud environments and infrastructure operated by LG Uplus
- Customer-facing services and internal business systems provided by LG Uplus
3.3 Sponsorship and/or Affiliation
LGUPLUS-CSIRT is organised under the information security function of LG Uplus and is funded internally by the company.
3.4 Authority
LGUPLUS-CSIRT is authorised to conduct investigation, analysis and response activities for security incidents within its constituency, on the basis of the internal information protection policies of LG Uplus and applicable legislation.
4. Policies
4.1 Types of Incidents and Level of Support
LGUPLUS-CSIRT addresses all types of information security incidents which occur, or threaten to occur, within its constituency. The level of support given will vary depending on the type and severity of the incident, the scope of impact, the importance of the affected assets and the resources available at the time.
Priority is determined based on the following factors.
- Attack level — attack method, accessibility of the target, resulting impact
- Damage status — scale of damage and likelihood of propagation
- Functional impact — current and likely future impact on services and business functions
- Asset importance — criticality of the affected assets
- Recoverability — time and resources required for recovery
4.2 Co-operation, Interaction and Disclosure of Information
LGUPLUS-CSIRT co-operates with relevant domestic organisations and the security community in order to prevent and respond to security incidents.
All information processed by LGUPLUS-CSIRT is handled in accordance with internal information classification policy. Personal data and customer information are protected in accordance with applicable legislation. Where it becomes necessary to share information with third parties, the consent of the information owner is obtained beforehand.
4.3 Communication and Authentication
For information classified as public, LGUPLUS-CSIRT uses conventional methods such as unencrypted electronic mail. To ensure the security of communication involving sensitive information, PGP-encrypted electronic mail or telephone will be used.
5. Services
5.1 Incident Response
Incident Triage
- Investigating whether an incident has indeed occurred
- Determining the extent and impact of the incident
Incident Coordination
- Determining the initial cause of the incident and the vulnerability exploited
- Facilitating contact with other internal departments and external parties involved
- Facilitating contact with appropriate authorities and law enforcement, if necessary
- Composing announcements to users, where applicable
Incident Resolution
- Incident analysis — evidence collection, tracking and tracing
- On-site response and recommendations for securing affected systems
- Vulnerability analysis and recommendations for remediation
5.2 Proactive Activities
- Announcements including threat information, vulnerability warnings and security advisories
- Intrusion detection and 24/7 security monitoring
- Technology watch and analysis of security trends
- Security audits and vulnerability assessments
- Security awareness activities for employees
6. Incident Reporting Forms
There is no specific form for reporting incidents. Please send your report to isoc@lguplus.com including the information below.
- Reporter information — name, organisation and contact details
- Date and time of the incident, including the time zone
- Affected systems — domains, IP addresses or service names
- Description of the incident and observed symptoms
- Supporting evidence such as relevant logs or screenshots
- Any actions already taken
If your report contains sensitive information, please encrypt it using the PGP public key.
7. Disclaimers
While every precaution will be taken in the preparation of information, notifications and alerts, LGUPLUS-CSIRT assumes no responsibility for errors or omissions, or for damages resulting from the use of the information contained within.