GlossaryISO 27001

ISMS

Short answer

An ISMS (Information Security Management System) is the set of policies, processes, roles and controls an organisation uses to manage information security risks in a systematic way. ISO 27001 defines its requirements and is the standard used to certify it.

What an ISMS includes

An ISMS brings together a security policy, a defined scope, a risk assessment method, a risk treatment plan, the controls that result from it, assigned responsibilities and the records that prove the controls work. It is a way of running security, not a single tool.

How it is maintained

An ISMS follows a cycle of planning, implementing, checking and improving. Internal audits and management reviews check whether it is working, and nonconformities lead to corrective actions.

ISMS and certification

ISO 27001 is the standard that defines the requirements for an ISMS. Certification proves to customers and partners that the system meets those requirements, as verified by an accredited certification body.

Related terms

Keep reading on this topic

ISO 27001 information security management: scope, risk treatment, Annex A controls, internal audit and the certification audit process, explained.

Go to the topic hub