2026 ISMS-P Certification Prep: The Complete Checklist of 102 Controls and Common Findings
📌 If you need mandatory-scope rules, the application process, timeline, and cost, see ISMS-P mandatory scope, process, and cost: complete overview. This post focuses on item-by-item checks of the 102 criteria and how to handle common findings.
"Where do I even start with certification prep?"
That is the first question newly assigned ISMS-P owners ask. Leadership says the organization must be certified this year, but opening the criteria document reveals 102 densely packed items—and it is unclear where to begin.
This post is a coaching-style guide to cut through that overwhelm. Follow this sequence: how to determine whether you are in scope → a 6-month prep roadmap → domain-by-domain checks and evidence → top 10 common findings → a copy-and-use self-assessment checklist. This is not a product roundup. It is strictly about the evidence and procedures you need to pass the audit.
ISMS vs. ISMS-P, and Determining 2026 Mandatory Scope
Start with the difference between the two certifications.
- ISMS (Information Security Management System): Audits the information security domain only (16 management-system + 64 protection-measure controls = 80 items)
- ISMS-P (Information Security and Personal Information Management System): Adds 22 personal-information lifecycle requirements, for a total of 102 items
Choose ISMS-P if you handle personal information at scale; choose ISMS if you are primarily focused on infrastructure and service security. With the 2026 Personal Information Protection Act amendments and the spread of MyData, personal-information processing controls have tightened, and more organizations have been moving to ISMS-P.
Mandatory-scope decision flow (text)
If you answer "yes" to any of the questions below, you are in mandatory scope for ISMS certification. (If you also process personal information, consider expanding to ISMS-P.)
Q1. Are you an ISP (internet access / telephone service) provider? → Yes: in scope
Q2. Are you an IDC (colocation / internet data center) operator? → Yes: in scope
Q3. Is information and communications service revenue KRW 10 billion or more? → Yes: in scope
Q4. Did you have 1 million+ average daily users over the last 3 months? → Yes: in scope
Q5. Are you a university with 10,000+ enrolled students? → Yes: in scope
Q6. Are you a tertiary general hospital with 100+ beds? → Yes: in scope
Q7. Is annual revenue/income KRW 150 billion or more AND
information and communications service revenue KRW 10 billion
or 1 million+ average daily users? → Yes: in scope
─ All no → voluntary (optional) applicantPractitioner tip: For SaaS/cloud-based services, the core issue is how far your certification scope extends. Split IaaS/PaaS provider responsibilities from yours with a RACI, and collect the CSP's existing certificates (ISMS, ISO 27017, etc.) as outsourced-processing evidence—scope definition becomes much easier.
D-6 month prep roadmap
If this is your first time, plan for at least six months. Here is the timeline with deliverables.
| Timing | Phase | Key deliverables |
|---|---|---|
| D-6 months | Current-state analysis & scope | Information asset inventory, service/org profile, gap analysis report |
| D-5 months | Policies & procedures | Information security policy, guidelines/procedures, committee charter |
| D-4 months | Risk assessment | Asset identification & risk assessment report, DoA (risk acceptance criteria) |
| D-3 months | Apply protection measures | Information security implementation plan, control-implementation evidence |
| D-2 months | Internal audit & training | Internal audit report, employee training completion records |
| D-1 month | Certification application | Application form, operating specification, at least 2 months of operating evidence |
| D-Day onward | Document & on-site audit → remediate findings | Audit findings report, evidence of completed remediation |
Note in particular that you need at least two months of operating evidence as of the application date. If you write policies and apply immediately, you will get findings for insufficient operating evidence.
Core checks and practical evidence by the three certification domains
The 102 items are grouped into these three domains.
| Domain | # of items | Representative controls (number · name) | Example evidence |
|---|---|---|---|
| 1. Establish & operate the management system | 16 | 1.1.1 Management involvement / 1.2.1 Information asset identification / 1.2.3 Risk assessment / 1.4.2 Management system review | InfoSec committee minutes, information asset inventory, risk assessment report, DoA, internal audit report |
| 2. Protection measure requirements | 64 | 2.5.x Access control / 2.6.x Authentication & authorization / 2.7.x Encryption / 2.9.x System & service operations | Access request/approval log, privilege review report, encryption policy, retained access logs |
| 3. Personal information lifecycle requirements | 22 | 3.1.x Collection safeguards / 3.3.x Outsourcing & provision / 3.4.x Destruction / 3.5.x Data subject rights | Personal information processing inventory, consent form templates, processor inspection reports, destruction log, personal information processing policy |
Evidence cannot be an abstract claim that "we manage it"—it must be proven in documents. For example, access logs must actually exist for 6 months on general systems and 1 year or more on personal-information processing systems, and destruction must be recorded in a destruction log and a destruction confirmation.
Top 10 findings auditors actually raise—and how to fix them
These are the findings auditors almost always catch. Each is structured as finding → root cause → remediation.
- Access-privilege reviews not performed on schedule (2.5): Policy requires quarterly/semiannual reviews, but they never happen → no owner, or other work takes priority → put review dates on the calendar and retain a review report every cycle.
- Access-log review and retention gaps (2.9): Logs accumulate, but there is no evidence of regular review → no review process → review monthly, record the checklist and any anomaly handling, and meet retention (6 months / 1 year).
- Risk assessment not linked to DoA (1.2): Risks are assessed but not tied to acceptance criteria or protection measures → DoA criteria never defined → document the DoA and map treatment plans to risks that exceed it.
- No evidence of personal-information destruction (3.4): Verbal "we deleted it" only → no destruction log → operate a destruction log with date/time, items, method, and owner.
- Processors never inspected (3.3): Contract signed, annual inspection skipped → weak sense of management accountability → inspect at least annually with a processor checklist and keep the report.
- Password/encryption policy not implemented (2.7): Policy exists, but plaintext storage and weak settings persist → not reflected in system config → verify one-way/strong encryption for resident registration numbers, passwords, etc.
- Policy vs. actual operations mismatch: Documents don't match the floor → policies were copied and never adapted → rewrite policies to a workable level, then accumulate operating evidence.
- Information asset inventory not kept current (1.2.1): New servers and SaaS omitted → weak change management → asset register/decommission process plus quarterly refresh.
- Privacy notice incomplete (3.5): Outsourcing and third-party sharing omitted → policy not kept current → align the personal information processing policy with actual processing and keep it publicly posted on the website.
- Internal audit is a formality: Recorded as "no issues" with zero findings → lack of independence/expertise → run a real checklist-based audit and record corrective actions for every finding.
Conclusion: Self-assessment checklist and next actions
Finally, a self-assessment checklist you can copy and use immediately. Change ☐ to ☑ when you have evidence for each item.
[Establish & operate the management system]
- ☐ An InfoSec committee is in place and minutes show management participation (1.1)
- ☐ The information asset inventory is up to date (1.2.1)
- ☐ The risk assessment report is linked to the DoA (1.2)
- ☐ A substantive internal audit has been performed at least annually (1.4)
[Protection measure requirements]
- ☐ Access request, approval, and review logs are maintained on a regular cycle (2.5)
- ☐ Privilege and account-management policy matches actual operations (2.6)
- ☐ Password and encryption policy is applied in the systems (2.7)
- ☐ Access logs are reviewed regularly and retained for 6 months / 1 year (2.9)
[Personal information lifecycle requirements]
- ☐ Personal information processing inventory and consent templates are in order (3.1)
- ☐ Processors are inspected at least annually and reports are retained (3.3)
- ☐ Destruction can be proven with a destruction log (3.4)
- ☐ The personal information processing policy matches actual processing and is publicly available (3.5)
The core message: "Prove it with operating evidence, not just documents." Certification is not a one-and-done event—surveillance audits (years 1 and 2) and a recertification audit (year 3) follow—so the surest way to pass is to put review cycles on the work calendar and run the system continuously. This week, start with a mandatory-scope self-check and a gap analysis.
FAQ
Q. Should we apply for ISMS or ISMS-P? A. If you process personal information at scale, go ISMS-P (102 items). If you are primarily infrastructure/service security, ISMS (80 items) is enough. MyData and customer-data-driven services almost always fit ISMS-P.
Q. How long does certification prep take? A. For a first-time effort, plan at least six months. You need two or more months of operating evidence as of the application date, so applying right after writing policies will produce findings for insufficient operating evidence.
Q. How do we set certification scope if we use cloud (SaaS)? A. Separate CSP responsibilities from yours with a RACI, and collect the CSP's certificates as outsourced-processing evidence. The audit scope is the data, accounts, and configurations you control directly.
Nodelog는 모든 콘텐츠의 내용과 출처를 공개 전에 검토합니다. 환경(OS·버전)에 따라 결과가 달라질 수 있는 기술 정보는 공식 문서와 함께 확인하며, 검토 기준과 정정 원칙은 편집 정책에서 안내합니다. 오류를 발견하시면 이메일로 제보해 주세요 — 확인 후 신속히 정정합니다.
Comments
Be the first to comment.