What is an ISMS (information security management system)?
An ISMS is the part of an organisation's management system that sets out the instruments and methods with which management steers information security. This is how the German Federal Office for Information Security (BSI) describes it in chapter 3.1 of BSI Standard 200-1. The requirements for such a system are set out in clauses 4 to 10 of ISO/IEC 27001, against which an ISMS can be certified.
An ISMS protects information in every form: in IT systems, on paper and in what employees know.
How to build an ISMS step by step is described in the guide ISMS implementation.
An ISMS has four components
According to chapter 3.1 of BSI Standard 200-1, an ISMS has four components. The right-hand column assigns each component the clauses of ISO/IEC 27001 that match its subject; the assignment is this page's, not the BSI's.
| Component under BSI Standard 200-1 | What it includes | Clauses of ISO/IEC 27001 |
|---|---|---|
| Management principles | duties of management, performance monitoring, continual improvement | 5, 9, 10 |
| Resources | staff, time and budget for the security process | 7 |
| Employees | involvement of staff in the security process | 7 |
| Security process | information security policy with security objectives and strategy, security concept, security organisation | 4, 5.2, 5.3, 6, 8 |
What the ISMS and any certificate cover is set by the ISMS scope under clause 4.3.
How does an ISMS work?
An ISMS derives its measures from risks and reviews them in a recurring cycle. BSI Standard 200-1 describes this cycle as the PDCA cycle of planning, implementation, monitoring of success and improvement.
- Plan: the organisation sets the scope and objectives, assesses the risks and selects measures.
- Do: the measures are introduced and operated, and staff are trained.
- Check: metrics, internal audits and the management review show whether the measures work.
- Act: deviations are corrected, and after major changes the cycle starts again with planning.
The reference set for the selection is Annex A of ISO/IEC 27001 with 93 controls. The Statement of Applicability records which of them apply and why.
ISMS, ISO 27001 and IT security management: five terms distinguished
The terms denote different things: a system, standards, a methodology and a management task. The table separates them by whether a certificate is possible.
| Term | What it denotes | Certifiable |
|---|---|---|
| ISMS | the management system the organisation operates | yes, against ISO/IEC 27001 |
| ISO/IEC 27001 | international standard with the requirements for an ISMS | is itself the audit benchmark |
| ISO/IEC 27002 | guidance on implementing the controls in Annex A | no |
| BSI IT-Grundschutz | the BSI's methodology with Standards 200-1 to 200-3 and requirement catalogues | through ISO 27001 certification on the basis of IT-Grundschutz |
| IT security management | the management task that is carried out through the ISMS | no |
BSI Standard 200-1 describes itself as fully compatible with ISO/IEC 27001. An organisation that works to IT-Grundschutz therefore builds an ISMS that can be measured against the standard.
Is an ISMS a legal requirement?
No German law requires every company to run an ISMS. Several laws do, however, require components of an ISMS from specific groups:
| Who | Provision | What is required |
|---|---|---|
| Essential and important entities under NIS2 | § 30 of the German BSI Act (BSIG) | appropriate, proportionate and effective risk management measures, including policies on risk analysis |
| Operators of critical facilities | § 39(1) BSIG | proof of implementation every three years, first at a date set by the BSI |
| Financial entities | Article 6 of Regulation (EU) 2022/2554 (DORA) | a documented ICT risk management framework |
| Controllers and processors under the GDPR | Article 32(1)(d) GDPR | a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures |
None of these provisions requires an ISO/IEC 27001 certificate. A certificate becomes mandatory when a customer makes it a contractual condition. An ISMS bundles the evidence for each of these duties in one management framework.
Rizzqo models the scope as a set of assets
Rizzqo carries the scope of an ISMS as an asset register. It holds primary assets such as information, processes and services, linked to the systems, applications, sites and service providers that support them. ISO/IEC 27001 and ISO/IEC 27002 are held as requirement catalogues.
The category of an asset determines which requirements appear on it. The owner answers them there with a justification and evidence and finalises them under name and timestamp. From these answers Rizzqo computes coverage for the check phase of the cycle, and daily snapshots show how it develops up to the management review.