/보안/2026 ISMS-P Certification Prep Checklist: A Practitioner's Guide to 102 Controls and Common Findings
SecurityISMS-P 인증 준비ISMS-P 102개 항목

2026 ISMS-P Certification Prep Checklist: A Practitioner's Guide to 102 Controls and Common Findings

A hands-on guide for first-time ISMS-P owners. It covers mandatory-scope determination, a 6-month roadmap, evidence for the 102 certification criteria, the top 10 audit findings, and a copy-and-use self-assessment checklist.

2026 ISMS-P Certification Prep Checklist: A Practitioner's Guide to 102 Controls and Common Findings

2026 ISMS-P Certification Prep: The Complete Checklist of 102 Controls and Common Findings

📌 If you need mandatory-scope rules, the application process, timeline, and cost, see ISMS-P mandatory scope, process, and cost: complete overview. This post focuses on item-by-item checks of the 102 criteria and how to handle common findings.

"Where do I even start with certification prep?"

That is the first question newly assigned ISMS-P owners ask. Leadership says the organization must be certified this year, but opening the criteria document reveals 102 densely packed items—and it is unclear where to begin.

This post is a coaching-style guide to cut through that overwhelm. Follow this sequence: how to determine whether you are in scope → a 6-month prep roadmap → domain-by-domain checks and evidence → top 10 common findings → a copy-and-use self-assessment checklist. This is not a product roundup. It is strictly about the evidence and procedures you need to pass the audit.

ISMS vs. ISMS-P, and Determining 2026 Mandatory Scope

Start with the difference between the two certifications.

  • ISMS (Information Security Management System): Audits the information security domain only (16 management-system + 64 protection-measure controls = 80 items)
  • ISMS-P (Information Security and Personal Information Management System): Adds 22 personal-information lifecycle requirements, for a total of 102 items

Choose ISMS-P if you handle personal information at scale; choose ISMS if you are primarily focused on infrastructure and service security. With the 2026 Personal Information Protection Act amendments and the spread of MyData, personal-information processing controls have tightened, and more organizations have been moving to ISMS-P.

Mandatory-scope decision flow (text)

If you answer "yes" to any of the questions below, you are in mandatory scope for ISMS certification. (If you also process personal information, consider expanding to ISMS-P.)

CODE
Q1. Are you an ISP (internet access / telephone service) provider?            → Yes: in scope
Q2. Are you an IDC (colocation / internet data center) operator?              → Yes: in scope
Q3. Is information and communications service revenue KRW 10 billion or more? → Yes: in scope
Q4. Did you have 1 million+ average daily users over the last 3 months?       → Yes: in scope
Q5. Are you a university with 10,000+ enrolled students?                      → Yes: in scope
Q6. Are you a tertiary general hospital with 100+ beds?                       → Yes: in scope
Q7. Is annual revenue/income KRW 150 billion or more AND
    information and communications service revenue KRW 10 billion
    or 1 million+ average daily users?                                        → Yes: in scope
   ─ All no → voluntary (optional) applicant

Practitioner tip: For SaaS/cloud-based services, the core issue is how far your certification scope extends. Split IaaS/PaaS provider responsibilities from yours with a RACI, and collect the CSP's existing certificates (ISMS, ISO 27017, etc.) as outsourced-processing evidence—scope definition becomes much easier.

D-6 month prep roadmap

If this is your first time, plan for at least six months. Here is the timeline with deliverables.

TimingPhaseKey deliverables
D-6 monthsCurrent-state analysis & scopeInformation asset inventory, service/org profile, gap analysis report
D-5 monthsPolicies & proceduresInformation security policy, guidelines/procedures, committee charter
D-4 monthsRisk assessmentAsset identification & risk assessment report, DoA (risk acceptance criteria)
D-3 monthsApply protection measuresInformation security implementation plan, control-implementation evidence
D-2 monthsInternal audit & trainingInternal audit report, employee training completion records
D-1 monthCertification applicationApplication form, operating specification, at least 2 months of operating evidence
D-Day onwardDocument & on-site audit → remediate findingsAudit findings report, evidence of completed remediation

Note in particular that you need at least two months of operating evidence as of the application date. If you write policies and apply immediately, you will get findings for insufficient operating evidence.

Core checks and practical evidence by the three certification domains

The 102 items are grouped into these three domains.

Domain# of itemsRepresentative controls (number · name)Example evidence
1. Establish & operate the management system161.1.1 Management involvement / 1.2.1 Information asset identification / 1.2.3 Risk assessment / 1.4.2 Management system reviewInfoSec committee minutes, information asset inventory, risk assessment report, DoA, internal audit report
2. Protection measure requirements642.5.x Access control / 2.6.x Authentication & authorization / 2.7.x Encryption / 2.9.x System & service operationsAccess request/approval log, privilege review report, encryption policy, retained access logs
3. Personal information lifecycle requirements223.1.x Collection safeguards / 3.3.x Outsourcing & provision / 3.4.x Destruction / 3.5.x Data subject rightsPersonal information processing inventory, consent form templates, processor inspection reports, destruction log, personal information processing policy

Evidence cannot be an abstract claim that "we manage it"—it must be proven in documents. For example, access logs must actually exist for 6 months on general systems and 1 year or more on personal-information processing systems, and destruction must be recorded in a destruction log and a destruction confirmation.

Top 10 findings auditors actually raise—and how to fix them

These are the findings auditors almost always catch. Each is structured as finding → root cause → remediation.

  1. Access-privilege reviews not performed on schedule (2.5): Policy requires quarterly/semiannual reviews, but they never happen → no owner, or other work takes priority → put review dates on the calendar and retain a review report every cycle.
  2. Access-log review and retention gaps (2.9): Logs accumulate, but there is no evidence of regular review → no review process → review monthly, record the checklist and any anomaly handling, and meet retention (6 months / 1 year).
  3. Risk assessment not linked to DoA (1.2): Risks are assessed but not tied to acceptance criteria or protection measures → DoA criteria never defined → document the DoA and map treatment plans to risks that exceed it.
  4. No evidence of personal-information destruction (3.4): Verbal "we deleted it" only → no destruction log → operate a destruction log with date/time, items, method, and owner.
  5. Processors never inspected (3.3): Contract signed, annual inspection skipped → weak sense of management accountability → inspect at least annually with a processor checklist and keep the report.
  6. Password/encryption policy not implemented (2.7): Policy exists, but plaintext storage and weak settings persist → not reflected in system config → verify one-way/strong encryption for resident registration numbers, passwords, etc.
  7. Policy vs. actual operations mismatch: Documents don't match the floor → policies were copied and never adapted → rewrite policies to a workable level, then accumulate operating evidence.
  8. Information asset inventory not kept current (1.2.1): New servers and SaaS omitted → weak change management → asset register/decommission process plus quarterly refresh.
  9. Privacy notice incomplete (3.5): Outsourcing and third-party sharing omitted → policy not kept current → align the personal information processing policy with actual processing and keep it publicly posted on the website.
  10. Internal audit is a formality: Recorded as "no issues" with zero findings → lack of independence/expertise → run a real checklist-based audit and record corrective actions for every finding.

Conclusion: Self-assessment checklist and next actions

Finally, a self-assessment checklist you can copy and use immediately. Change ☐ to ☑ when you have evidence for each item.

[Establish & operate the management system]

  • ☐ An InfoSec committee is in place and minutes show management participation (1.1)
  • ☐ The information asset inventory is up to date (1.2.1)
  • ☐ The risk assessment report is linked to the DoA (1.2)
  • ☐ A substantive internal audit has been performed at least annually (1.4)

[Protection measure requirements]

  • ☐ Access request, approval, and review logs are maintained on a regular cycle (2.5)
  • ☐ Privilege and account-management policy matches actual operations (2.6)
  • ☐ Password and encryption policy is applied in the systems (2.7)
  • ☐ Access logs are reviewed regularly and retained for 6 months / 1 year (2.9)

[Personal information lifecycle requirements]

  • ☐ Personal information processing inventory and consent templates are in order (3.1)
  • ☐ Processors are inspected at least annually and reports are retained (3.3)
  • ☐ Destruction can be proven with a destruction log (3.4)
  • ☐ The personal information processing policy matches actual processing and is publicly available (3.5)

The core message: "Prove it with operating evidence, not just documents." Certification is not a one-and-done event—surveillance audits (years 1 and 2) and a recertification audit (year 3) follow—so the surest way to pass is to put review cycles on the work calendar and run the system continuously. This week, start with a mandatory-scope self-check and a gap analysis.

FAQ

Q. Should we apply for ISMS or ISMS-P? A. If you process personal information at scale, go ISMS-P (102 items). If you are primarily infrastructure/service security, ISMS (80 items) is enough. MyData and customer-data-driven services almost always fit ISMS-P.

Q. How long does certification prep take? A. For a first-time effort, plan at least six months. You need two or more months of operating evidence as of the application date, so applying right after writing policies will produce findings for insufficient operating evidence.

Q. How do we set certification scope if we use cloud (SaaS)? A. Separate CSP responsibilities from yours with a RACI, and collect the CSP's certificates as outsourced-processing evidence. The audit scope is the data, accounts, and configurations you control directly.

확인 정보
✦ ✦ ✦
편집 검토 · Editorial Review

Nodelog는 모든 콘텐츠의 내용과 출처를 공개 전에 검토합니다. 환경(OS·버전)에 따라 결과가 달라질 수 있는 기술 정보는 공식 문서와 함께 확인하며, 검토 기준과 정정 원칙은 편집 정책에서 안내합니다. 오류를 발견하시면 이메일로 제보해 주세요 — 확인 후 신속히 정정합니다.

편집 책임 · Nodelog 기술 편집팀·발행 · ·업데이트 ·

Comments

Be the first to comment.