Information security management system (ISMS)
Also known as: ISMS
The set of policies, roles, processes and records an organisation uses to run its information security in a planned, repeatable way.
Draft - this entry has not been reviewed yet.
Formal
A management system, as specified in ISO 27001, that defines its scope, assigns roles and ownership, chooses controls from a risk assessment, measures how well they work and improves them through internal audit and management review.
In plain English
Like the way a well-run restaurant kitchen works - not one recipe, but the routines for buying, storing, cooking, cleaning and checking that keep every meal safe, whoever is on shift.
In practice
A Danish software company with 80 staff names a security lead, writes down which systems the work covers, repeats its risk assessment every year, keeps a list of chosen controls and has management review the status each quarter.
Why it matters
One-off security fixes fade or are forgotten when the person behind them leaves; a standing system of owners, reviews and records keeps the work going as people and threats change.
Technical deep dive
ISO/IEC 27001:2022 does not define an ISMS as a tool or a binder of documents but as a set of interacting processes that the organisation must "establish, implement, maintain and continually improve" (clause 4.4). Its boundary is fixed in clause 4.3: the scope statement has to take account of internal and external issues (4.1), the requirements of interested parties (4.2) and the interfaces and dependencies between the organisation's own activities and those performed by others. Scope is the most consequential design decision in the whole system. A certificate covering "the hosting platform in Aarhus" says nothing about the support desk abroad or the SaaS product built on top, and customers, auditors and NIS2 supervisors increasingly read the scope statement before they read the certificate.
The core mechanics form a closed loop of documented information. Risk assessment (6.1.2) requires defined risk acceptance criteria, identification of risks to confidentiality, integrity and availability, named risk owners, and a method that produces consistent, valid and comparable results when repeated. Risk treatment (6.1.3) selects controls from any source, compares them with Annex A so that nothing necessary is overlooked, and produces the Statement of Applicability plus a treatment plan whose residual risks the risk owners formally accept. Objectives (6.2) must be measurable where practicable, and 6.3, added in 2022, requires changes to the ISMS itself to be planned. Clause 8 repeats the assessments at planned intervals or when significant changes occur, clause 9 covers monitoring and measurement (9.1), internal audit (9.2) and management review (9.3), and clause 10 deals with nonconformities through correction, root-cause analysis and corrective action.
Because ISO 27001 uses the harmonized structure shared with ISO 9001, ISO 22301 and ISO/IEC 42001, an ISMS is often run as one part of an integrated management system with common document control, a joint internal audit programme and a single management review. ISO/IEC 27701:2025 follows the same skeleton as a standalone privacy information management system, no longer an extension that presupposes 27001.
Typical failure modes are a "paper ISMS" in which the policies exist but the risk register has not changed since the certification audit, a scope drawn to exclude the difficult parts of the business, risk owners who are IT staff rather than managers with authority to accept risk, and metrics that count activity (courses held) rather than effect. An ISMS also differs from a catalogue such as the CIS Controls or an outcome framework such as the NIST CSF: those describe what to achieve, whereas the ISMS is the governance machinery that decides which of those things apply, who owns them and whether they work. Accredited certification over a three-year cycle of initial, surveillance and recertification audits verifies that machinery, not that the organisation is secure.
What to learn first
Everything this builds on, foundations first.
- CIA triad
- →Security policy
- →Threat
- →Asset
- →Vulnerability
- →Impact
- →Likelihood
- →Risk
- →Risk management
- →Information security management system (ISMS)
Relationships
- Consists of
- Security metrics (KPIs)
- Requires
- Risk managementSecurity policy
- Mandated by
- ISO 27001
Sources & further reading
Standards & official texts
- ISO/IEC 27001:2022 - Information security management systems - Requirements · ISO/IEC
Course material
- Cyber Security Fast Track - Ordliste
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Mentioned in
Check yourself
Loading…