ISO/IEC 27001:2022 Information Security Management System (ISMS): A Practitioner's Commentary, Vol. 2 — People, Physical & Technological Controls (Annex A.6–A.8) & Certification
Implementing and auditing the controls — and passing certification
- 저자
- Lee Chungon (Mark)
- 펴낸곳
- ISC Press
- ASIN
- B0H7JQHBR4
한국어판 보기: ISO/IEC 27001:2022 정보보안경영시스템(ISMS) 실무해설서 — 하권: 통제 구현·심사 대응편
이 책은
이런 분께 권합니다
Control Owners
Implementing people, physical and technological controls
27001 Candidates
Completing the evidence base for certification
Audit Response
Handling nonconformities and corrective action (CAPA)
Aspiring Auditors
Learning what auditors actually check
예제소스·부록 자료실
이 책의 예제소스·부록 실습 자료는 자료실 게시판에서 내려받으실 수 있습니다.
저자 소개
Lee Chungon (Mark) is the founder of ISC (International Standard Certification) and a working lead auditor.
- ISO/IEC 27001 · 27701 · 22301 · 42001 Lead Auditor
- Founded ISC (2017); conducts ISO management-system audits
- Certified ISMS (information security management system) consultant
- Graduate of Hanyang University Graduate School — Computer Science, Offensive Security, and Law
- AI engineer and developer — builds ERP/CRM, LMS, and global e-commerce systems end to end
- Author of the ISC Security Series — practitioner-focused commentaries from onboarding to certification
Written from recurring findings on real certification audits — focused on how to operate the standard, not merely read it.
책만으로 부족하다면, 직접 도와드립니다
ISC.studio는 인증기관이 운영하는 웹·앱 스튜디오입니다. ISO/IEC 27001 인증 취득부터 심사 대응까지 무료 상담을 받아보세요.
Why this book
Controls and certification, in one volume.
-
Controls built
A.6–A.8, implemented
People, physical and technological controls implemented and audited, with evidence examples.
Annex A technological controls in full
-
Audit response
Prevent findings early
The nonconformities auditors raise most often — and the response documents that close them.
Written by a working auditor
-
Ready to use
Checklists & maps
Practical appendices — control mapping tables and audit checklists — to finish certification.
Pairs with Vol. 1
Inside Vol. 2
What you get
-
A.6 People
Screening, awareness and disciplinary controls with evidence
-
A.7 Physical
Access, equipment and media physical-security controls
-
A.8 Technological
Access control, cryptography, logging and vulnerability management
-
Audit response
Nonconformities and corrective action (CAPA)
-
Appendices
Control mapping tables and audit checklists
-
Certification
Vol. 1 + Vol. 2 across build → operate → audit