Frameworks

What is an ISMS?

An ISMS (information security management system) is the set of policies, processes, roles, and controls an organization uses to manage information security risk in a structured, repeatable way. It is the central concept of ISO/IEC 27001.

Definition

An information security management system (ISMS) is a documented, risk-based system of policies, processes, roles, and controls for protecting the confidentiality, integrity, and availability of information. It is managed as an ongoing cycle, not a one-time project.

Background

The ISMS is the core idea of ISO/IEC 27001:2022. The standard is organized around it: clauses 4 to 10 define the management-system requirements (context, leadership, planning, support, operation, performance evaluation, and improvement), and Annex A provides 93 controls, grouped into four themes, that you apply based on your risk assessment. The point of a management system is that security is governed and continually improved, rather than handled ad hoc.

Why it matters

A working ISMS is what an ISO 27001 certification body assesses. More practically, it is what keeps security consistent as a company grows: decisions are recorded, risks are owned, and controls are reviewed on a cadence instead of depending on a few people remembering to do things.

Step by step

  1. Define the scope and context: what information, systems, and parts of the business the ISMS covers.
  2. Secure leadership commitment and assign roles and responsibilities.
  3. Run a risk assessment and decide how to treat each risk.
  4. Select and implement controls (Annex A is the reference set) and record the decisions in a Statement of Applicability.
  5. Operate the controls, collect evidence, and train people.
  6. Monitor, audit internally, review at management level, and improve, then repeat the cycle.

Examples

  • A SaaS company defines its ISMS scope as the production platform and the teams that build and run it, then expands scope later.
  • A managed service provider runs one ISMS across its own operations and uses it as the backbone for the frameworks its clients ask about.

Common mistakes

  • Writing a shelf-full of policies nobody follows instead of a system people actually operate.
  • Scoping the ISMS so broadly on day one that it becomes unmanageable.
  • Treating certification as the finish line rather than maintaining the management cycle afterward.

FAQ

Is an ISMS the same as ISO 27001?

No. An ISMS is the management system itself; ISO/IEC 27001 is the standard that specifies requirements for one and against which you can be certified.

Do I need an ISMS for SOC 2?

SOC 2 does not require a formal ISMS, but the same building blocks (risk assessment, policies, controls, evidence) support both, so an ISMS makes SOC 2 easier too.

Related

ISO 27001 in Keel → What is ISO 27001? → What is a Statement of Applicability? → What policies are required for ISO 27001? →

Do this in Keel, not a spreadsheet

Keel is the AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.

Start free