Planning information security and personal data protection events/campaigns

The purpose is to improve, compared with last year, awareness campaigns that are not defined in the regulations and often end merely with the distribution of promotional gifts, by referring to best practices from various organizations, given the current situation in which the performance of events and campaigns such as Information Security Day or Personal Information Protection Day, held monthly or annually, is gradually declining. These events must now move beyond gift-distribution activities organized by the Information Security Team and become events in which all employees participate and uphold security together. It is necessary to build mutual understanding through the establishment of a communication system for embedding security into the organization. Ultimately, employees must have a good understanding of information security and the Personal Information Protection Act so that the organization can realistically protect itself from hacking and insider threats. Since the departments other than the Security Team—including those responsible for commissioning various projects, managing entrusted service providers, controlling applications and security settings, planning various informatization projects, and conducting IT audits—are designated to take overall responsibility, the Security Team is distributing security-related tasks among the respective departments. However, the current situation is that each department is merely expressing dissatisfaction. This opportunity should therefore be used to move away from that situation, as internal consultative bodies alone are insufficient. Security-related scoring criteria must be reflected in the powerful personnel evaluation system. Through unannounced audits, those who fail to comply should be disciplined through pay reductions or suspension, while those who properly observe security requirements and demonstrate achievements in support of security should receive substantial financial rewards through an incentive system. Security must be embedded in the organization so that employees take the initiative themselves. Accordingly, department and individual evaluation KPIs should be adjusted through a report to the CEO under the direction of the CISO. In addition, through a system for designating department-level information security officers and personnel in charge, the organization should strengthen its human security framework against hacking and information leakage—including the leakage of documents managed by each department and the management of service providers—by providing position allowances for these responsibilities.

1 learners are taking this course

Level Beginner

Course period 6 months

AI
AI
security training
security training
Engineer information security
Engineer information security
ISMS-P
ISMS-P
AI
AI
security training
security training
Engineer information security
Engineer information security
ISMS-P
ISMS-P

What you will gain after the course

  • Planning information security and personal data protection events

  • Information Security and Privacy Protection Campaign Planning

🔐 Do you hold a personal data protection event every year, only to hand out promotional gifts and call it a day?

“We have to hold a Personal Information Protection Day event, but… what should we do?”

🎁 Distribute tumblers or commemorative gifts
📧 Send out privacy protection information emails
📌 Post posters on the website or internal bulletin board
📝 Hold a simple quiz event

We conduct personal information protection training and awareness-raising activities every year, but when it comes time to actually plan a Personal Information Protection Day event or an internal campaign, it is often difficult to find relevant examples to refer to.

In particular, if you are a privacy officer who has wondered, “How do other companies actually run personal data protection or information security events?” or “Is there an idea we could use as-is at our organization?”, this course may be helpful. 💡

This training does not explain general theories about personal information protection events.

This is a practical, narration-free course that examines, one by one, examples of personal information protection and information security events and campaigns created and run by actual companies, along with PPT screens, to explore how they can be applied in our own organization or company.


🎯 How did Gabia use “Security Bingo”?

“Conduct personal information protection training.”

Encouraging people to participate directly can be more memorable than simply providing instructions like this.

In this lecture, we will examine Gabia’s “Security Bingo Challenge” case study. Rather than simply communicating security guidelines, it uses bingo as an interactive form of content to encourage employees to participate directly in security activities.

🎲 What happens when you turn security guidelines into bingo content
🎲 Whether this approach can also be applied to privacy campaigns
🎲 How simple quiz events differ from participatory challenges

You can see this through the actual case study screens.


💻 How did Golfzon turn “Shadow IT” into a campaign?

One of the issues that privacy and information security managers constantly struggle with is unauthorized programs and IT assets.

However, instead of simply announcing, “Please do not use unauthorized programs,” Golfzon approached it through a campaign called “Find Shadow IT”.

In particular, the PPT covers a case where the goal of strengthening the identification and management of unauthorized IT assets was implemented as a screen saver campaign.

🖥️ How can a campaign using an in-house screensaver be structured?
🔍 How can employees naturally encounter security messages in their work environment?
📢 Is there a way to continuously raise awareness without holding a separate large-scale event?

You can see ideas from a real company.


🙋‍♂️ How did LINE Plus create an “interactive campaign and quiz”?

“We’ll hold a personal information protection quiz event.”

However, simply creating a few true-or-false questions and waiting for people to participate makes it difficult to expect either a high participation rate or a memorable impact.

In this lecture, we will examine LINE Plus’s interactive campaigns and quiz examples together with actual materials.

📱 How participation is encouraged
🎮 How content-based campaigns, rather than simple training, are structured
🧩 How to turn personal information protection messages into engaging questions and participation methods

If you’ve been wondering, “Our organization also needs to run a quiz event— is there a fun way to do it?” this is an example worth considering.


🧩 Did Lotte E&C Turn Personal Information and Information Security into a “Word Puzzle”?

Personal data protection terminology is difficult.

Then, instead of simply explaining these difficult terms in training materials, why not turn them into a crossword puzzle event?

This training also introduces a case study of Lotte E&C’s crossword puzzle event.

🔐 How to use personal data protection terms as quiz content
🧠 How to help employees naturally remember concepts as they solve the questions
🎁 How to transform events and prize giveaways from simple gift distribution into interactive content

You’ll see this through real-world examples.


🎢 Lotte World even leveraged its mascot and a “security mock exam”!

“Our company doesn’t have a character that we can use to promote personal information protection.”

You don’t necessarily need to create a new character.

Lotte World operated overlay content using its existing mascot and a cybersecurity mock exam case.

In this lecture, you can explore the following ideas in particular.

🎭 How to use an existing corporate mascot in an information security campaign
📸 Examples of overlay content that can encourage employee participation
📝 A security mock exam designed to feel like taking a real test
🏆 How to combine participation and fun rather than simply completing training

If you thought, “Can security training really be made like a mock exam?” check out the actual case.


🎬 Lotte Card produced its training videos in-house instead of outsourcing them.

There’s always something to consider when conducting personal information protection training.

“Shouldn’t video production be handled by a professional company?”

However, Lotte Card used an example of a training video produced in-house by its information security team.

In this lecture, we will examine how an actual company produced and utilized its own information security content.

🎥 What content can a personal information protection department create itself?
🎬 How can you create engaging content without necessarily producing highly professional videos?
📢 What are some ways to move beyond the same PPT training repeated every year?

This is a particularly useful case study for practitioners creating personal information protection training materials.


🔥 How did Toss run its internal privacy & security campaign?

Viva Republica's internal personal data protection and security campaign case is also covered in this course.

We will explore through case studies how to develop privacy and information security not merely as separate tasks, but as internal campaigns that employees across the organization can actively participate in.

You can also compare how different companies communicate information security messages through design and content by examining Samwha Paint Industrial Co., Ltd.'s information security guidelines and Yanolja Company's Information Security Day poster example.


🎵 An Information Security Campaign Song and Music Video Created with AI?

One of the cases to pay particular attention to in this course is Shinsegae DF’s use of AI to create an information security campaign song and music video.

“AI can be used this way in a personal information protection campaign?”

Rather than simply explaining how to use AI, let’s look at a case where AI was integrated into actual information security promotional content.

🎵 Could information security guidelines be turned into a song?
🎬 Could an educational video be made in the form of a music video?
🤖 Could privacy officers also plan new promotional content themselves by using AI?

If you want to move away from promotion centered around conventional posters and informational emails, this is where you can find new ideas.


📌 Real-world corporate cases covered in this lecture

🎲 Gabia – Security Bingo Challenge
💻 Golfzon – Shadow IT Discovery Campaign
🙋 LINE Plus – Interactive Campaign & Quiz
🧩 Lotte Engineering & Construction – Crossword Puzzle Event
🎭 Lotte World – Mascot Overlay
📝 Lotte World – Security Mock Exam
🎬 Lotte Card – Training Video Produced In-House by the Information Security Team
🔥 Viva Republica – In-House Personal Data & Security Campaign
📢 Samhwa Paints Industrial – Information Security Guidelines
🎵 Shinsegae Duty Free – Information Security Campaign Song and Music Video Using AI
🖼️ Bucketplace – Information Security Day Poster

This lecture is not about saying, “You need to hold a personal information protection event.”

This course examines, through case studies, what other companies actually did, what screens and content they created, and what ideas privacy officers can use as references at their own organizations.

While preparing events such as Personal Information Protection Day, Information Security Day, and Personal Information Protection Week every year…

❌ “I should just make a poster first.”
❌ “Should I offer prizes and come up with a few quiz questions?”
❌ “I guess we can do something similar to last year’s event.”

If you’ve found yourself wondering that,

This time, review real-world examples from companies all at once and plan your own personal information protection promotions, events, and campaigns for your organization. 🚀🔐

Why did Gabia create a security bingo game, why did Golfzon run a Shadow IT discovery campaign, and why did Lotte World create a security mock exam?

Discover those ideas and real-world cases in this online training. 🎯

Recommended for
these people

Who is this course right for?

  • Information security promotions/events/campaigns/training coordinator

  • Person in charge of privacy protection promotions/events/campaigns/training

Need to know before starting?

  • At least 4 years of experience planning information security promotions, events, campaigns, and training.

  • At least 4 years of experience planning personal information protection promotions, events, campaigns, and training

Hello
This is jueygrace

424

Learners

43

Reviews

4.0

Rating

50

Courses

A top domestic privacy expert with over 8 years of experience in privacy education, advisory, and consulting (performed 1st-tier financial sector ISMS-P/ISO27701/internal audits/regular evaluations; achieved S-grades for all consulting firms in public institution protection level evaluations for 6 years; conducted public institution impact assessments; served as a privacy instructor for major corporations for 3 years; established mid-to-long-term strategies (master plans) for manufacturing companies; and performed AI security reviews/deliberations, etc.)

 

Experience and Performance

 

1. Tutoring

2. Education

3. Consulting

4. Project Design/Support

5. Q&A (Inquiry Response)

6. Task delegation

7. Establishment of procedures

8. Procedure improvement

9. Status survey, diagnosis, and reporting

10. Establishment of plans for introducing new technologies, etc.

11. Establishment of Information Security/Personal Credit Information Protection Master Plan (Establishment of Mid-to-Long-term Strategy)

12. ISMS, ISMS-P evidence preparation and audit response

13. ISO27001, ISO27701 evidence preparation and audit response

14. Preparation of evidence and report writing for Personal Information Protection Level Assessment

15. Cybersecurity Status Assessment

16. Support for the enactment and revision of regulations, guidelines, procedures, manuals, and guides

17. Support for ongoing information security evaluation

18. Personal information leakage incident simulation drill

19. DRP, BCP Business Continuity Drill

20. Establishment of DRP and BCP business continuity plans

21. PbD(Privacy by Design) procedure and system menu planning

22. Establishment of SbD (Security by Design) procedures and security review criteria

23. Establishment and improvement of DevSecOps procedures

24. AI System Security Review

25. AI system personal information protection inspection (customized)

26. Support for pseudonymization, including review of pseudonymization adequacy

27. Designation of pseudonymization officers and definition of business R&R

28. Inspection of the storage and transmission system for personal information in access control systems (smart gates, fingerprint authentication, in-house apps)

29. Promotion, campaign planning and support

30. Planning and production of promotional materials, quizzes, and participatory events

31. Establishment of improvement plans for information security and personal information protection organizations

32. Checking the adequacy of information security and personal information protection budgets and establishing improvement plans

33. Support for collecting opinions on the revision of regulations and procedures, and support for conducting surveys

34. Support for exception handling for non-encrypted personal information and inquiry reason input

35. Support for producing Information Protection Committee reporting materials, preparing agenda for the Personal Information Protection Working-level Council, and supporting the attendance of advisory members

36. Support for personal information processing system inspection

37. Support for creating personal information flow tables and personal information flowcharts

38. Support for H/W and public/private cloud asset identification and establishment of asset classification standards

39. Support for asset C/S/O assessment and risk assessment report preparation

40. Support for drafting protection measures and improvement plan reports

41. BPF malware inspection

42. Inspection of shared folder usage status

43. Creation of critical data flow diagrams

44. Establishment of control system security monitoring plan

45. Support for trustee status investigation

46. Support for status survey of fixed video data processing devices

47. Support for status survey of mobile visual data processing devices

48. Support for personal information file updating survey

49. Support for investigating targets of personal information impact assessments

50. CPO Best Practice Sharing

51. Sharing CEO Best Practices

52. Establishment of open source management guidelines

53. Establishment of cloud management system

54. Vulnerability analysis and evaluation of electronic financial infrastructure

55. Vulnerability analysis and evaluation of critical information and communications infrastructure

56. Security Review Committee

57. Evaluation of the adequacy of firewall and security equipment (WAF, VPN, etc.) policies

58. Investigation of Account and Permission Status and Evaluation of Adequacy

59. Investigation and adequacy assessment of log and backup status

60. Investigation and adequacy assessment of personal information collection, storage, and provision status

61. Investigation of status and adequacy assessment of collection, storage, and provision of critical information

62. Adequacy assessment of security threats and security management for PC integrated security solutions, antivirus, DLP, DRM, data transfer, email, SSO, etc. (Solution bypass)

63. Assessment of Server Access Control and DB Access Control Policy Adequacy

64. Investigation and adequacy assessment of EOS and patch status

65. IP and Port Scanning

66. Investigation and inspection of app personal information protection status

67. Privacy Center Operation

68. 24/365 Personal Information Protection Help Desk Operation

69. Consent withdrawal system planning

70. Personal information inquiry and access system planning

71. Preparation of reporting materials for CISO/CPO/CEO

72. R&D Project

73. Consent form inspection checklist

74. Privacy Policy Review Checklist

75. Children's Privacy Inspection

76. Access log (inquiry, download) misuse and abuse consulting

77. CCTV De-identification Consulting

78. Penetration Testing

79. Web Vulnerability Assessment

80. App Vulnerability Assessment

81. CS Vulnerability Assessment

82. Mock Training

83. Tabletop Exercise (TTX)

84. Network Penetration

85. Inspection of Internal Management Plan Implementation Status

86. Personal information management status inspection

87. Trustee Inspection

88. On-site inspection of trustees

89. Service Security Inspection

90. On-site service security inspection

91. Creation and management of the list of handlers to keep it up to date

92. Review of access rights and establishment of criteria for differential granting

93. Creation of Security Pledge and Personal Information Pledge

94. Establishment and revision of access control policies

95. Personal information meetings, inspections, and support for affiliated and subordinate organizations

96. Discussion of group company personal information protection policies and measures

97. Establishment of personal information destruction plans and investigation of destruction status (destruction methods, destruction results)

98. Review of legal grounds for personal information retention and inspection of separate storage status

99. Establishment of procedures for requesting personal information access and investigation of current status

100. Improvement of procedures and status survey for requests such as viewing personal video information (including objections)

101. Support for applying and improving matters regarding refusal of automated collection and requests for withdrawal of consent, and support for improvement

102. Support for the application and improvement of the right to data portability for personal information

103. Support for personal information processing policy review and improvement measures (appropriateness, understanding, readability, etc.)

104. Personal information collection, use, and provision inquiry consent form review and system consent status check (minimum collection, form review)

105. Investigation of consent status (Investigation of CI/DI collection, comparison of DB storage status, default consent checks, etc.)

106. Personal information file consolidation survey and new personal information file survey

107. Inspection of the appropriateness of the grounds for processing personal information files

108. Review and re-establishment of password creation rules

109. Full investigation of access control (IP, duplicate login restriction, session blocking)

110. Full investigation of encryption status for internal and external transmissions

111. Personal Information Exposure Check

112. Source code inspection

113. Establishment of internal employee personal information management standards (labor-management consultation)

114. Production and design review of personal information processing policies in the form of webtoons, posters, easy-to-understand versions, and versions for children/the elderly and employees

115. Disclosure of outsourcing status via QR, bulletin boards, etc., use of icons and characters, and disclosure of personal information processing policy in mobile environments

116. Appropriateness of personal information consent and agent identity verification during landline processing at call centers, branch offices, etc.

117. Review of appropriateness for recording servers and STT (Speech to Text)

118. Review of the adequacy of transmission and storage for SMS/Email/Notification Talk transmission servers

119. Identification of business processes (by unit task), review of security and personal information protection adequacy

120. Generative AI utilization training and promotion (Cyber Security Diagnosis Day, Personal Information Protection Day)

121. Preparation of Personal Information Protection Master Plan and Personal Information Protection Implementation Plan

122. Support for information disclosure and public data provision tasks

123. Computerization of consent forms (improvement of AlimTalk viewing consent)

124. Review of overseas personal information protection laws

125. Information security inspection for new technology environments and personal information protection inspection business support

126. Support for the task of changing consent forms->information guides

127. Destruction status and appropriateness of destruction (cases of reports due to notifications such as emails to data subjects because data remained)

128. Cases of exposure of resident registration numbers, etc., via email due to employee error (establishment of prevention systems)

129. Establishment and application of procedures to block personal information uploads on internal and external bulletin boards, etc.

130. Consultation on requesting safety measures for the use or provision of personal information for purposes other than intended, or for personal information partnerships, and review of the reply regarding safety measures.

131. Support for trustee contract renewal (contract modification)

132. Comparison of pros and cons for SNS simple login reorganization and change support (SNS simple login vulnerabilities)

133. Vulnerability assessment of identity verification methods such as resident registration cards or mobile phone identity verification (numerous incident cases)

134. Consultation on changes to the division of duties

135. Internal management plan employee training

136. Establishment of reward and incentive plans

137. Support for PET (Privacy Enhancing Tech) implementation and training/consulting on synthetic data

138. Personal information protection consulting in new technology environments (Cloud, 5G, Generative AI, AI systems, drones), etc.

139. Deriving a plan to strengthen personal information security measures

140. Analysis and evaluation of internal management plans

141. Legal Compliance Assessment

142. e-Privacy Plus certification preparation and audit response

143. APEC CBPR certification preparation and audit response

144. CSAP certification preparation and audit response

145. Disclosure of ESG Information Security and Personal Information Protection Activities

146. Preparation and response for research institute institutional evaluation

147. Preparation and response for central administrative agency evaluations

148. Writing news press releases and creating slogans

149. Zero Trust Maturity Assessment

150. Establishment of improvement plans for trustee management

151. CVE Inspection

152. Management of trustee personal information processing flow and provision ledger

153. Investigation and inspection of personal credit information masking status

154. Inspection of wireless LAN usage status

155. Establishment and advancement of security management systems for public/private cloud environments

156. Individual Business Trustee Inspection

More
Published: 
Last updated: 

Reviews

Not enough reviews.
Please write a valuable review that helps everyone!

jueygrace's other courses

Check out other courses by the instructor!

Similar courses

Explore other courses in the same field!

Limited time deal

$3.30

25%

$4.40