ISO/IEC 27701:2025 Privacy Information Management Systems (PIMS) in Practice: A Practitioner's Commentary
From implementation and operation through to the certification audit — a working auditor's field guide
- 저자
- Lee Chungon (Mark)
- 펴낸곳
- ISC Press
- ASIN
- B0HCPKLVP4
한국어판 보기: ISO/IEC 27701:2025 개인정보보호경영시스템(PIMS) 실무 — 상권: 표준의 이해와 PII 고유 통제
이 책은
이런 분께 권합니다
CPOs & DPOs
Building a privacy information management system from scratch
PIMS Candidates
Preparing for PIMS certification and control mapping
27001 Owners
Extending an existing ISMS to integrated 27701 certification
Aspiring Auditors
Studying for 27701 Lead Auditor with practical grounding
예제소스·부록 자료실
이 책의 예제소스·부록 실습 자료는 자료실 게시판에서 내려받으실 수 있습니다.
저자 소개
Lee Chungon (Mark) is the founder of ISC (International Standard Certification) and a working lead auditor.
- ISO/IEC 27001 · 27701 · 22301 · 42001 Lead Auditor
- Founded ISC (2017); conducts ISO management-system audits
- Certified ISMS (information security management system) consultant
- Graduate of Hanyang University Graduate School — Computer Science, Offensive Security, and Law
- AI engineer and developer — builds ERP/CRM, LMS, and global e-commerce systems end to end
- Author of the ISC Security Series — practitioner-focused commentaries from onboarding to certification
Written from recurring findings on real certification audits — focused on how to operate the standard, not merely read it.
책만으로 부족하다면, 직접 도와드립니다
ISC.studio는 인증기관이 운영하는 웹·앱 스튜디오입니다. ISO/IEC 27001 인증 취득부터 심사 대응까지 무료 상담을 받아보세요.
Why this book
A 27701 commentary from a working auditor.
-
Auditor's lens
What counts as evidence
The processing records and control evidence a PIMS audit actually checks, clause by clause.
27701 Lead Auditor
-
27001 integrated
Extend without rework
Map PIMS onto an existing ISMS so you reach integrated certification without starting over.
Integrated audit practice
-
Law-ready
GDPR & privacy law
Controls linked to privacy-law requirements so they double as regulatory evidence.
Controller / processor split
Inside the book
What you get
-
The standard
Structure of 27701:2025 and its link to 27001
-
PII controls
Annex A.1/A.2 controller & processor controls
-
Common controls
Annex A.3 common security controls, mapped
-
Build & run
PIMS implementation roadmap and operation
-
Audit response
Common findings and how to answer them
-
Appendices
Checklists and control-mapping tables