Most companies that believe they have an ISMS actually have a folder of policies. Someone wrote a security policy, a password policy and a backup policy, saved them to a shared drive, and considered the matter closed. It is a reasonable start, but it is not a management system. The difference is not the number of documents — it is their nature.
What an ISMS does that a folder of policies does not
A policy states an intention: "we will run backups this way." An ISMS is the process that decides why that policy exists, checks that it is followed, measures whether it works and corrects it when it stops. The policy is the photograph; the ISMS is the film.
Put another way: a document does not know when it has gone stale. A management system does, because it includes the mechanisms - internal audit, management review, risk management - that detect when reality has drifted from the paper and force action.
Clauses 4 to 10: where the ISMS actually lives
In ISO/IEC 27001:2022, the management system is defined in clauses 4 to 10, and these are exactly what a loose document does not cover:
- Clause 4 — Context: what the organisation protects, for whom, and within what scope.
- Clause 5 — Leadership: management owns security as its own responsibility, not delegated to a document.
- Clause 6 — Planning: a documented, repeatable risk assessment methodology and measurable security objectives.
- Clause 7 — Support: resources, competence, awareness and control of documented information.
- Clause 8 — Operation: carrying out risk treatment day to day.
- Clause 9 — Performance evaluation: measuring, internal audit and management review.
- Clause 10 — Improvement: handling nonconformities and applying corrective action.
That is the line between "having policies" and "having an ISMS": clauses 4 to 10 are live governance. A standalone policy has no risk methodology, no measurable objectives, no internal audit programme and no management review.
Annex A sits under the management system, not instead of it
Annex A of ISO 27001:2022 gathers 93 controls grouped into four themes: organisational, people, physical and technological. It is the part most people recognise as "security": access control, encryption, vulnerability management, event logging.
The common mistake is to start there. Annex A controls are not applied wholesale: they are selected on the basis of risk, and that selection is justified in the statement of applicability. Without the governance layer of clauses 4 to 10 above them, the controls are loose measures with no criterion explaining why they exist, who reviews them and what happens when they fail. Annex A sits under the management system, not instead of it.
How to tell whether you have an ISMS or just policies
Four quick questions separate the two. If the answer to most is "no", you have policies:
- Is there a documented risk assessment methodology that is repeated regularly?
- Are there measurable security objectives, and someone who reviews whether they are met?
- Is an internal audit programme run, with findings and owners?
- Does management formally review the state of security and take decisions on it?
An ISMS answers "yes" to all four and leaves evidence of each. A folder of policies answers "no" to almost all of them, however well the documents are written.
Why this matters for certification: documented, verified, operated
Here is the practical consequence. A management system, on its own, does not produce an ISO 27001 certificate. The certificate is issued by an accredited certification body after an audit, and that audit checks three distinct things: that the ISMS is documented, that it is verified (there is evidence the controls run) and that it is operated (it works day to day, not only on audit day). A folder of policies passes, at most, the first. You can go deeper on that distinction in what a certification audit actually tests.
From policies to a system that holds
The jump from "having policies" to "having an ISMS" is not writing more documents: it is operating clauses 4 to 10 continuously — the risk assessments, the internal audits, the management reviews — month after month, not once a year before the audit. That continuous work is exactly what collapses when it depends on one person with ten other priorities.
Qalea operates that management system continuously: it does not hand over a folder of policies and leave, but keeps alive the process that produces, verifies and reviews them, so that what is on paper still describes what actually happens.
Find out whether what you have today is an ISMS or just a good set of documents.








