/보안/ISMS-P Certification Prep: The 7 Most Common Audit Findings and a Checklist
SecurityISMS-P정보보호인증

ISMS-P Certification Prep: The 7 Most Common Audit Findings and a Checklist

Not sure where to start with ISMS-P certification? This guide covers whether you are a mandatory subject, the typical 4–6 month prep process, and the audit findings that come up most often—laid out as symptom, checkpoint, and how to prepare

ISMS-P Certification Prep: The 7 Most Common Audit Findings and a Checklist

ISMS-P Certification Prep Checklist 2026 — Start with the Findings That Come Up Most

"We got the certificate, but the same findings keep coming up at every surveillance audit."

If you've been through ISMS-P even once, you'll nod at that. The problem isn't the findings themselves—it's that the cost of fixing them (re-audits, consulting, overtime) often exceeds the original consulting fee. That's even more true for SMEs and startups where a single security person, or an infra/dev lead wearing two hats, is carrying the whole load.

This post is a practical checklist. It starts with whether your company is a mandatory subject, then walks through the items that most often produce nonconformities (findings) in real audits, in symptom → checkpoint → how to prepare order. The tables are built so you can self-assess just by reading them—copy and use them if you're already in prep.

⚠️ Revenue, timeline, and fee figures in this article are reference values to aid understanding. Mandatory-subject criteria and fees change when notices are revised, so always check the latest KISA announcements and notices.

1. Is Our Company a Mandatory Subject? ISMS vs. ISMS-P

Let's start with the terms.

  • ISMS (Information Security Management System): certifies the information security domain only
  • ISMS-P (Information Security and Personal Information Protection Management System): information security plus protection at each stage of personal information processing

In other words, if your service actually handles personal information—sign-up, payments, marketing consent, and so on—ISMS-P is the right fit. Conversely, if personal information is a small share of what you do (for example, B2B infrastructure services), ISMS alone may be enough.

2026 ISMS Mandatory-Subject Decision Table

CategorySubject criteria (examples)When ISMS alone may sufficeWhen ISMS-P is the better fit
ISP (telecommunications network service provider)Operators with nationwide circuit facilitiesLow share of personal information processingDirectly processes subscriber personal information
IDC (internet data center)Operates facilities for others' information and communications servicesSimple colocation/hostingProcesses tenant personal information under consignment
Revenue/income scaleAnnual revenue/income of KRW 150 billion or more, among other size thresholdsLow volume of personal information processingHolds a large member database
Number of usersDaily average of 1 million or more users as of the end of the previous yearMostly de-identified/anonymousProcesses large volumes of real-name/identifying information
Information and communications service revenueRevenue from information and communications services of KRW 10 billion or moreAlmost no personal informationMember- and payment-based services

The figures above are examples of representative criteria. Many companies also obtain certification voluntarily (even when not mandatory) to build trust or score points in bids. The trend of obtaining ISMS-P voluntarily even when it is not required has been especially clear among AI and SaaS startups in 2026.

2. Process, Timeline, and Cost at a Glance

From prep to certificate issuance typically takes 4–6 months. Larger scope or a first-time certification takes longer.

CODE
[Stage 1] Prep & gap analysis              (4–8 weeks)  Current-state assessment, policy setup, asset identification
   ↓
[Stage 2] Application & contract           (1–2 weeks)  Apply to the certification body, schedule audit dates
   ↓
[Stage 3] Pre-check (optional)             (1–2 weeks)  Mock audit to clear findings in advance
   ↓
[Stage 4] Main audit (desk + on-site)      (1–2 weeks)  Document & operational evidence review, interviews
   ↓
[Stage 5] Finding remediation              (2–6 weeks)  Address findings + submit evidence
   ↓
[Stage 6] Certification committee & issue  (2–4 weeks)  Deliberation/decision, then certificate issued

Cost Structure (scope and structure, not exact numbers)

ItemWhat it coversWhat drives variance by size
Audit feesPaid to the certification body; calculated from certification scope and headcountScope of application (number of services/systems) and employee count
Consulting feesGap analysis, documentation, mock-audit supportInternal capability; whether you prepare in-house
Solution costsLog management, access control, encryption, backup, etc.Maturity of existing infrastructure
Internal effortTime the owner spends (the most underestimated line)Dual-role load; state of existing documentation

💡 A note from the field: The line that most often goes missing from cost estimates is "internal effort." Consulting fees show up on the quote; the cost of your owner spending half of three months on certification does not. Securing the owner's available time when you set the schedule matters more than picking a consulting firm.

3. Checklist of Items That Frequently Produce Audit Findings (the core)

This is the main event. These are the items that repeatedly come back as nonconformities in real audits.

AreaSymptom (how it usually gets called out)CheckpointHow to prepare
Access control & account managementTerminated/unused accounts still active; shared admin accounts in useReconcile account issuance/revocation logs with actual system accounts; privilege review cycleQuarterly privilege re-review records, one person, one account, keep access-approval evidence
Log & access-record retentionAccess logs for personal information processing systems don't meet the retention period; weak anti-tamperingLog retention period (access records at least 6 months; downloads and similar have separate requirements) and integrityStore logs separately with access control; write regular inspection logs
Risk assessment documentsRisks identified but no DoA (acceptable risk level) rationale or treatment planTraceability: asset ID → threats/vulnerabilities → risk scoring → treatment planAnnual risk assessment records; residual risk approved by management
EncryptionPasswords/unique identifiers stored or transmitted unencrypted; no key managementScope of encryption in storage and transit; key generation, storage, and destruction proceduresDocument encryption policy and key-management procedures, plus evidence of application
Personal information flow diagramCollection-to-destruction flow doesn't match actual processing; consignment/third-party provision missingFlow diagram ↔ personal information processing policy ↔ actual system behavior must matchSet a refresh cycle for the flow diagram (update immediately on change)

If You Use Cloud (AWS, etc.) — Watch the Shared Responsibility Model

As more SaaS and cloud-based startups have appeared in 2026, questions about shared-responsibility findings have spiked. The key point: "our cloud provider is certified, so we're done" is not true.

  • Cloud provider responsibility: physical security, hypervisor, underlying infrastructure
  • Customer responsibility: OS and above, access permissions (IAM), security groups, encryption settings, log collection

Auditors look at configuration and operational evidence in the customer-responsibility zone. Document and evidence least-privilege IAM, S3 bucket public-access blocks, CloudTrail log retention, and similar controls.

4. The Real Game Is Maintenance — Preparing for Surveillance and Recertification Audits

An ISMS-P certificate is valid for 3 years. The structure in between looks like this:

  • Year 1: issuance
  • Years 2 and 3: annual surveillance audit (confirms you are maintaining the system)
  • After 3 years: recertification audit (essentially a full re-audit)

The most common failure pattern is "cramming operational evidence together right before the audit." Six months of inspection records all created on the same day—auditors spot that immediately. The right answer is to accumulate evidence in the ordinary course of work, which is why you need an annual routine calendar.

Annual Operational-Evidence Calendar Template

CadenceRecurring activityEvidence to keep
MonthlyBackup health check, security-patch statusBackup inspection logs, patch application records
QuarterlyAccess-privilege re-review, unused-account revocationPrivilege review results, account revocation log
Semi-annualDrills (phishing, incident response), vulnerability assessmentDrill after-action reports, remediation records
AnnualRisk assessment, information security training, internal auditRisk assessment report, training completion roster, audit results

Just putting this table on the calendar cuts the surveillance-audit burden roughly in half. The core idea: evidence is not something you manufacture—it's something you let accumulate.

Frequently Asked Questions (FAQ)

Q1. Should we get ISMS or ISMS-P? A. If you actually process personal information—members, payments, marketing, and so on—ISMS-P is the right fit. Infrastructure-style services with a low share of personal information may be fine with ISMS alone. Whether you are a mandatory subject is a separate call based on revenue and user counts.

Q2. Can we prepare in-house without consulting? A. Yes. For a first time, though, getting outside help at least for gap analysis and a mock audit usually costs less than a re-audit later. From the second recertification onward, many companies run it with internal capability.

Q3. What's the minimum prep time? A. Even if documentation and operations are reasonably in place, application to issuance is typically 4–6 months. If you're starting from a blank page, budget an extra 2–3 months just to close gaps.

Q4. Can the certificate be revoked at a surveillance audit? A. Yes—if you fail to remediate material findings by the deadline, or the management system is effectively not operating, the certificate can be revoked or suspended. That's why day-to-day operational evidence matters.

Q5. If we use cloud (AWS, etc.), how far does our responsibility go? A. Under the shared responsibility model, underlying infrastructure is the cloud provider's; OS and above (IAM, encryption, logs, security configuration) is yours. Auditors check configuration and operational evidence in the customer-responsibility zone.

Q6. The numeric thresholds keep changing—where do we check? A. Mandatory-subject criteria, audit fees, access-record retention requirements, and similar items change when notices are revised. Use KISA (Korea Internet & Security Agency) ISMS-P scheme announcements and the latest notices as the source of truth.

확인 정보
✦ ✦ ✦
편집 검토 · Editorial Review

Nodelog는 모든 콘텐츠의 내용과 출처를 공개 전에 검토합니다. 환경(OS·버전)에 따라 결과가 달라질 수 있는 기술 정보는 공식 문서와 함께 확인하며, 검토 기준과 정정 원칙은 편집 정책에서 안내합니다. 오류를 발견하시면 이메일로 제보해 주세요 — 확인 후 신속히 정정합니다.

편집 책임 · Nodelog 기술 편집팀·발행 · ·업데이트 ·

Comments

Be the first to comment.