What is the Standard Operating Procedure for Information Systems?
- Date2026.06.09
What is the Standard Operating Procedure for Information Systems?
The Standard Operating Procedure (SOP) for Information Systems is a set of defined guidelines designed to ensure the stable operation and efficient management of IT systems in administrative and public institutions. True to the word "standard," it provides common criteria and methods applicable across all organizations.
Institutions must adopt these procedures according to the guidelines set by the Ministry of the Interior and Safety (MOIS), but they can also define additional, detailed processes tailored to their specific characteristics, organizational structure, and service environments.
Based on the global ITIL V4 standard, this SOP is more than a simple manual or work instruction. It serves as a process-oriented operational framework to control and manage the entire IT system. Ultimately, it aims to minimize potential disruptions during system operations while enhancing overall stability and operational capabilities.
8 Major Processes of the Standard Operating Procedure for Information Systems

< Source: Ministry of the Interior and Safety >
The SOP outlines eight core processes across a three-stage structure: preventive, responsive, and post-incident management.
- Customer Service Request Management (CRM): Ensures various user service requests are received, categorized, routed, and resolved without omission within a specified timeframe.
- Change Management (CHM): Minimizes the service impact of system modifications through a structured process of request reception, planning, review, approval, execution, and testing.
- Event Management (EVM): Efficiently handles and prevents issues by monitoring, analyzing, and addressing various events that occur during system operations.
- Incident Management (INM): Secures service continuity by swiftly identifying, escalating, analyzing, and resolving system failures, while formulating measures to prevent recurrence.
- Problem Management (PBM): Prevents future incidents by identifying the root causes of unresolved issues and providing definitive solutions.
- Configuration Management (CFM): Maintains up-to-date configuration data by tracking the lifecycle and history of IT assets, providing accurate information to other processes.
- Backup Management (BKM): Guarantees service continuity by backing up data to protect against loss or damage from system failures or natural disasters.
- Service Level Agreement (SLA): Defines, agrees upon, monitors, measures, reports, and improves target IT service levels.
The preventive management stage secures system stability in advance to control issues before they arise. The responsive management stage focuses on minimizing service downtime and accelerating recovery when problems occur. Finally, the post-incident management stage prevents the repetition of identical issues by analyzing root causes and establishing preventative measures. This prevent-respond-improve structure effectively transforms system operations into a single, integrated operational cycle.
Information System Grading Criteria

< Source: Ministry of the Interior and Safety >
The MOIS classifies information systems into four grades, applying different levels of SOP implementation. Grades are calculated based on business impact (50%), number of users (40%), and service reach (10%). Level 1 and 2 systems must adopt all eight processes and mandatorily implement an SOP operating system, while Level 3 and 4 systems are recommended to apply five core processes and maintain proper record management.
However, these grading criteria are expected to change. According to an administrative notice recently released by the MOIS regarding IT system stability in public institutions, the impact on citizens' daily lives—or "public impact"—will soon take the highest priority (70%).
Information System SOP and ITSM

The Information System SOP is a management framework designed to ensure the stable operation of IT systems in public institutions, enabling a transition to standardized, data-driven operations. Although its implementation became mandatory in 2026, there is still a noticeable lack of awareness and preparation in the field.
If your organization is seeking the optimal way to adopt the SOP, an IT Service Management (ITSM) platform like 'E-GENE™ ITSM' can help build a system that fully meets MOIS standards. Based on the eight core SOP processes, E-GENE™ ITSM seamlessly connects each procedure and enables the recording and tracking of all tasks. For example, the Korea Gas Corporation successfully rebuilt its ITSM using E-GENE™ ITSM based on the SOP framework. By designing a customized process centered on the SOP, as recommended by the MOIS, they have demonstrated a best practice in implementation.
An ITSM system that supports SOP compliance is the first step toward strengthening public service continuity and enhancing system reliability. It establishes a single point of contact via an IT portal, introduces essential functions for adhering to the eight processes, and enables the proper storage and management of evidentiary data. By transitioning an institution's IT operations to a standardized, data- and record-driven framework through the SOP and ITSM, organizations can quantitatively manage service levels and significantly boost service quality, efficiency, and operational capabilities.