What an ISMS includes
An ISMS brings together a security policy, a defined scope, a risk assessment method, a risk treatment plan, the controls that result from it, assigned responsibilities and the records that prove the controls work. It is a way of running security, not a single tool.
How it is maintained
An ISMS follows a cycle of planning, implementing, checking and improving. Internal audits and management reviews check whether it is working, and nonconformities lead to corrective actions.
ISMS and certification
ISO 27001 is the standard that defines the requirements for an ISMS. Certification proves to customers and partners that the system meets those requirements, as verified by an accredited certification body.




