Information Security Management System (ISMS)

Systematic approach for managing sensitive business information according to ISO 27001 standards.

An ISMS (information security management system) is how an organisation runs information security as a system rather than a set of separate measures: with objectives, assigned responsibilities and a repeating cycle of plan, do, check and act. ISO 27001 is the international standard that sets the requirements for an ISMS, and the standard it is certified against.

An ISMS has a few fixed parts: a defined scope, an information security policy, a risk assessment and a plan for treating those risks, a Statement of Applicability listing the chosen controls, and evidence that those controls work. Internal audits and a management review close the cycle, so the system keeps pace as the organisation changes.

An ISMS is not software but the set of agreements and processes. ISMS software, such as Tidal Control, keeps the system current by holding policies, risks, controls and evidence in one place. A well-run ISMS protects the confidentiality, integrity and availability of information, and shows customers and auditors that security is demonstrably in order.

Frequently asked questions

What is an ISMS?
An Information Security Management System (ISMS) is a structured framework of policies, processes and controls that an organisation uses to manage information security risks systematically.
What is the ISMS in ISO 27001?
In ISO 27001, the ISMS is the management system (clauses 4–10) an organisation must establish, implement, maintain and continually improve; ISO 27001 specifies its requirements and is the standard the ISMS is certified against.
Why do you need an ISMS?
An ISMS gives you a repeatable, risk-based way to protect information, demonstrate compliance to customers and auditors, and improve security over time.
What is ISMS software?
Software that supports the ISMS: you record policies, risks, controls and evidence in it, schedule internal audits and see where the gaps are. It does not replace the ISMS, which remains the set of agreements and processes; the software keeps it up to date.