All articlesISO 27001

ISMS vs security policies: what's the difference?

ISMS vs security policies: what's the difference?

In short

  • An ISMS is a living governance process; a security policy is just one document inside it.
  • The ISMS lives in ISO 27001 clauses 4 to 10: from context to continual improvement.
  • Annex A (93 controls, four themes) is chosen by risk and sits under the management system, not instead of it.
  • Without a risk method, measurable objectives, internal audit and management review, you have policies, not an ISMS.
  • A management system alone does not produce the certificate: the audit checks it is documented, verified and operated.

What is an ISMS, and how is it different from having security policies?

An ISMS (information security management system) is the governance framework that defines how an organisation assesses risk, chooses controls, measures results and corrects them over time. Having security policies is not the same as having an ISMS: policies are documents; the ISMS is the living process that produces them, applies them and reviews them.

Most companies that believe they have an ISMS actually have a folder of policies. Someone wrote a security policy, a password policy and a backup policy, saved them to a shared drive, and considered the matter closed. It is a reasonable start, but it is not a management system. The difference is not the number of documents — it is their nature.

What an ISMS does that a folder of policies does not

A policy states an intention: "we will run backups this way." An ISMS is the process that decides why that policy exists, checks that it is followed, measures whether it works and corrects it when it stops. The policy is the photograph; the ISMS is the film.

Put another way: a document does not know when it has gone stale. A management system does, because it includes the mechanisms - internal audit, management review, risk management - that detect when reality has drifted from the paper and force action.

Clauses 4 to 10: where the ISMS actually lives

In ISO/IEC 27001:2022, the management system is defined in clauses 4 to 10, and these are exactly what a loose document does not cover:

  • Clause 4 — Context: what the organisation protects, for whom, and within what scope.
  • Clause 5 — Leadership: management owns security as its own responsibility, not delegated to a document.
  • Clause 6 — Planning: a documented, repeatable risk assessment methodology and measurable security objectives.
  • Clause 7 — Support: resources, competence, awareness and control of documented information.
  • Clause 8 — Operation: carrying out risk treatment day to day.
  • Clause 9 — Performance evaluation: measuring, internal audit and management review.
  • Clause 10 — Improvement: handling nonconformities and applying corrective action.

That is the line between "having policies" and "having an ISMS": clauses 4 to 10 are live governance. A standalone policy has no risk methodology, no measurable objectives, no internal audit programme and no management review.

Annex A sits under the management system, not instead of it

Annex A of ISO 27001:2022 gathers 93 controls grouped into four themes: organisational, people, physical and technological. It is the part most people recognise as "security": access control, encryption, vulnerability management, event logging.

The common mistake is to start there. Annex A controls are not applied wholesale: they are selected on the basis of risk, and that selection is justified in the statement of applicability. Without the governance layer of clauses 4 to 10 above them, the controls are loose measures with no criterion explaining why they exist, who reviews them and what happens when they fail. Annex A sits under the management system, not instead of it.

How to tell whether you have an ISMS or just policies

Four quick questions separate the two. If the answer to most is "no", you have policies:

  • Is there a documented risk assessment methodology that is repeated regularly?
  • Are there measurable security objectives, and someone who reviews whether they are met?
  • Is an internal audit programme run, with findings and owners?
  • Does management formally review the state of security and take decisions on it?

An ISMS answers "yes" to all four and leaves evidence of each. A folder of policies answers "no" to almost all of them, however well the documents are written.

Why this matters for certification: documented, verified, operated

Here is the practical consequence. A management system, on its own, does not produce an ISO 27001 certificate. The certificate is issued by an accredited certification body after an audit, and that audit checks three distinct things: that the ISMS is documented, that it is verified (there is evidence the controls run) and that it is operated (it works day to day, not only on audit day). A folder of policies passes, at most, the first. You can go deeper on that distinction in what a certification audit actually tests.

From policies to a system that holds

The jump from "having policies" to "having an ISMS" is not writing more documents: it is operating clauses 4 to 10 continuously — the risk assessments, the internal audits, the management reviews — month after month, not once a year before the audit. That continuous work is exactly what collapses when it depends on one person with ten other priorities.

Qalea operates that management system continuously: it does not hand over a folder of policies and leave, but keeps alive the process that produces, verifies and reviews them, so that what is on paper still describes what actually happens.

Find out whether what you have today is an ISMS or just a good set of documents.

Frequently asked questions

Do security policies count as an ISMS?

No. Security policies are documents that describe intentions. An ISMS is the process that assesses risk, decides which policies and controls are needed, checks they are followed and corrects them. Policies are a part of the ISMS, not the whole ISMS.

How does the ISMS relate to Annex A of ISO 27001?

Annex A of ISO 27001:2022 contains 93 controls grouped into four themes (organisational, people, physical and technological). Those controls are selected on the basis of risk and justified in the statement of applicability. Annex A operates underneath the management system defined in clauses 4 to 10.

Does an ISMS on its own give you the ISO 27001 certificate?

No. The ISO 27001 certificate is issued by an accredited certification body after an audit that checks the management system is documented, verified and operated day to day. Having the system in place is the prerequisite, but the certificate depends on the external audit.

Which ISO 27001 clauses define the ISMS?

Clauses 4 to 10 of ISO/IEC 27001:2022 define the management system: context, leadership, planning (including risk assessment), support, operation, performance evaluation (internal audit and management review) and continual improvement.

What is the difference between an ISMS and a security policy document?

A security policy describes what should be done in a specific area. An ISMS is the framework that decides which policies are needed based on risk, checks they are applied, measures their effectiveness and updates them. The policy is static; the ISMS is a cycle of continual improvement.

More articles

All articles