ISO/IEC 27001:2022 Information Security Management System (ISMS): A Practitioner's Commentary, Vol. 1 — Requirements (Clauses 4–10) & Organizational Controls (Annex A.5)
A working auditor's commentary — from building the ISMS to passing the audit
- 저자
- Lee Chungon (Mark)
- 펴낸곳
- ISC Press
- ASIN
- B0H7JD8MHP
한국어판 보기: ISO/IEC 27001:2022 정보보안경영시스템(ISMS) 실무해설서 — 상권: 관리체계 구축편
이 책은
이런 분께 권합니다
ISMS Owners
Standing up the management system and control framework
27001 Candidates
Preparing for ISMS certification
Risk & SoA
Building the risk assessment and Statement of Applicability
Integrated MS
Extending the ISMS to 27701 (PIMS) and 42001 (AIMS)
예제소스·부록 자료실
이 책의 예제소스·부록 실습 자료는 자료실 게시판에서 내려받으실 수 있습니다.
저자 소개
Lee Chungon (Mark) is the founder of ISC (International Standard Certification) and a working lead auditor.
- ISO/IEC 27001 · 27701 · 22301 · 42001 Lead Auditor
- Founded ISC (2017); conducts ISO management-system audits
- Certified ISMS (information security management system) consultant
- Graduate of Hanyang University Graduate School — Computer Science, Offensive Security, and Law
- AI engineer and developer — builds ERP/CRM, LMS, and global e-commerce systems end to end
- Author of the ISC Security Series — practitioner-focused commentaries from onboarding to certification
Written from recurring findings on real certification audits — focused on how to operate the standard, not merely read it.
책만으로 부족하다면, 직접 도와드립니다
ISC.studio는 인증기관이 운영하는 웹·앱 스튜디오입니다. ISO/IEC 27001 인증 취득부터 심사 대응까지 무료 상담을 받아보세요.
Why this book
A commentary written by a working auditor.
-
Auditor's lens
What counts as evidence
Clause by clause, what an auditor actually checks — and which documents trigger nonconformities.
Written by an ISO certification body
-
Requirements
Clauses 4–10, built out
The management-system requirements turned into policy, procedure and record — step by step.
Annex A.5 organizational controls
-
Integrated MS
27701 & 42001 ready
Cross-mapped to PIMS and AIMS so your ISMS extends to integrated certification without rework.
Integrated audit practice
Inside Vol. 1
What you get
-
Requirements
Clauses 4–10 as requirement → interpretation → evidence
-
Annex A.5
Organizational controls with worked document examples
-
Risk & SoA
Risk assessment method and Statement of Applicability
-
Cloud (A.5.23)
New 2022 controls including cloud services
-
Integration
Mapping points to 27701 and 42001
-
Templates
Policy/procedure skeletons and evidence checklists