ISMS (Information Security Management System)

An ISMS (information security management system) is the framework of policy, roles, risk method and measures through which an organisation steers and evidences information security. Its requirements are set out in ISO/IEC 27001, against which an ISMS can be certified. Unlike IT security, it covers information in every form, including on paper.

ISMSLast reviewed:

What is an ISMS (information security management system)?

An ISMS is the part of an organisation's management system that sets out the instruments and methods with which management steers information security. This is how the German Federal Office for Information Security (BSI) describes it in chapter 3.1 of BSI Standard 200-1. The requirements for such a system are set out in clauses 4 to 10 of ISO/IEC 27001, against which an ISMS can be certified.

An ISMS protects information in every form: in IT systems, on paper and in what employees know.

How to build an ISMS step by step is described in the guide ISMS implementation.

An ISMS has four components

According to chapter 3.1 of BSI Standard 200-1, an ISMS has four components. The right-hand column assigns each component the clauses of ISO/IEC 27001 that match its subject; the assignment is this page's, not the BSI's.

Component under BSI Standard 200-1What it includesClauses of ISO/IEC 27001
Management principlesduties of management, performance monitoring, continual improvement5, 9, 10
Resourcesstaff, time and budget for the security process7
Employeesinvolvement of staff in the security process7
Security processinformation security policy with security objectives and strategy, security concept, security organisation4, 5.2, 5.3, 6, 8

What the ISMS and any certificate cover is set by the ISMS scope under clause 4.3.

How does an ISMS work?

An ISMS derives its measures from risks and reviews them in a recurring cycle. BSI Standard 200-1 describes this cycle as the PDCA cycle of planning, implementation, monitoring of success and improvement.

  1. Plan: the organisation sets the scope and objectives, assesses the risks and selects measures.
  2. Do: the measures are introduced and operated, and staff are trained.
  3. Check: metrics, internal audits and the management review show whether the measures work.
  4. Act: deviations are corrected, and after major changes the cycle starts again with planning.

The reference set for the selection is Annex A of ISO/IEC 27001 with 93 controls. The Statement of Applicability records which of them apply and why.

ISMS, ISO 27001 and IT security management: five terms distinguished

The terms denote different things: a system, standards, a methodology and a management task. The table separates them by whether a certificate is possible.

TermWhat it denotesCertifiable
ISMSthe management system the organisation operatesyes, against ISO/IEC 27001
ISO/IEC 27001international standard with the requirements for an ISMSis itself the audit benchmark
ISO/IEC 27002guidance on implementing the controls in Annex Ano
BSI IT-Grundschutzthe BSI's methodology with Standards 200-1 to 200-3 and requirement cataloguesthrough ISO 27001 certification on the basis of IT-Grundschutz
IT security managementthe management task that is carried out through the ISMSno

BSI Standard 200-1 describes itself as fully compatible with ISO/IEC 27001. An organisation that works to IT-Grundschutz therefore builds an ISMS that can be measured against the standard.

No German law requires every company to run an ISMS. Several laws do, however, require components of an ISMS from specific groups:

WhoProvisionWhat is required
Essential and important entities under NIS2§ 30 of the German BSI Act (BSIG)appropriate, proportionate and effective risk management measures, including policies on risk analysis
Operators of critical facilities§ 39(1) BSIGproof of implementation every three years, first at a date set by the BSI
Financial entitiesArticle 6 of Regulation (EU) 2022/2554 (DORA)a documented ICT risk management framework
Controllers and processors under the GDPRArticle 32(1)(d) GDPRa process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures

None of these provisions requires an ISO/IEC 27001 certificate. A certificate becomes mandatory when a customer makes it a contractual condition. An ISMS bundles the evidence for each of these duties in one management framework.

Rizzqo models the scope as a set of assets

Rizzqo carries the scope of an ISMS as an asset register. It holds primary assets such as information, processes and services, linked to the systems, applications, sites and service providers that support them. ISO/IEC 27001 and ISO/IEC 27002 are held as requirement catalogues.

The category of an asset determines which requirements appear on it. The owner answers them there with a justification and evidence and finalises them under name and timestamp. From these answers Rizzqo computes coverage for the check phase of the cycle, and daily snapshots show how it develops up to the management review.

Browse all entriesBack to top

Frequently asked questions

See compliance run on your real assets

Rizzqo turns framework requirements into owned tasks on the assets you already have, and prices the risk in real money.

Made in GermanyHosted in your countryMulti-framework