This solution provides a consulting service concerning information security management according to ISO/IEC 27001 and policy design in order to apply with the organization’s NIST Cybersecurity Framework. Also, it allows the organization to make an Information Security Risk Treatment Plan that is consistent with information security policy and objectives. This service includes document arrangements of Statement of Applicability : SOA which is used in ISMS as its defined scope together with implementation documents and other documents for operations according to the standard. In addition, the service includes providing consultation on document preparation for Effectiveness Measurement of the information security management together with monitoring and reporting outcomes according to the specified criteria.