Skip to main content

Information Security Management System

Also known as: ISMS

The documented set of policies, procedures, and accountability that an organisation uses to manage information-security risk over time.

Written by Askara Solutions editorial team · Updated

An information security management system is the institutional shape your security work takes. Policies that say what is required, procedures that say how it is done, roles that say who is accountable, and evidence that the whole thing operated as designed across an audit period.

The ISMS is what makes ISO 27001 different from a security project. A project ends when the deliverables are accepted. An ISMS is the discipline that continues afterwards: the management review that runs every quarter, the internal audit that fires every year, the corrective actions that close the loop when something is found wanting. Auditors look as much at whether the ISMS has been operating as they do at whether the controls are in place.

The minimum content of an ISMS is set out in the body of ISO 27001 (clauses 4 through 10) rather than in Annex A. Scope, leadership, planning, support, operation, performance evaluation, improvement. Each clause produces an artefact. Each artefact is something the auditor will ask to see. The Askara Solutions agent treats those artefacts as the visible output of work your team is already doing, rather than paperwork bolted on at the end.

Related terms

  • ISO 27001

    International standard that defines the requirements for an information security management system (ISMS), including risk assessment, control selection, and management review.

  • Statement of Applicability

    ISO 27001 document that records, for every Annex A control, whether it is applied, why it is applied, and what evidence demonstrates that it operates.

  • Annex A

    The catalogue of 93 information security controls in ISO/IEC 27001:2022, organised into four themes (organisational, people, physical, technological), referenced from the Statement of Applicability.

  • Risk Register

    The single source of truth recording every identified risk, its assessment, the control treatment chosen, the owner, and the review date.

Authoritative sources

Where to read more.