An ISMS is the set of policies, processes and records an organisation uses to manage information security decisions, rather than the security tools themselves.
The short answer
An information security management system, or ISMS, is a documented way of running security: what you protect, who owns each decision, how risks are assessed, and how you check the arrangement still works. ISO 27001 certifies the management system, not the individual tools.
The word “system” misleads people. An ISMS is not software you install. It is closer to how a finance function works: written rules, named owners, a regular review, and records proving the rules were followed.
What an ISMS contains
Four things, and none of them is a product.
Scope and context
Which parts of the business, systems and locations are covered, and who the interested parties are.
Risk process
A repeatable method for identifying, analysing and treating information security risk, with named risk owners.
Controls and policies
The measures selected to treat those risks, and the written rules that govern them.
Leadership commitment
An approved policy, allocated resources and defined responsibilities, signed off at the top.
Monitoring and audit
Internal audits, measurement of whether controls work, and a management review at a set interval.
Improvement
A process for handling nonconformities, recording corrective action and feeding it back into the system.
How it operates
An ISMS runs as a loop rather than a project. ISO 27001 does not name the Plan-Do-Check-Act cycle in the 2022 edition, but the clause structure still follows it, and auditors look for evidence that the loop turned at least once before certification.
Setting the scope
Scope is the first decision and the one that shapes cost. A narrow scope certifies less but completes faster. An unrealistically narrow scope, such as excluding the product that customers actually buy, gets challenged by the certification body and by buyers reading the certificate.
| Scope element | What to state |
|---|---|
| Products and services | Which offerings are covered, named as customers would recognise them |
| Locations | Offices, data centres and cloud regions in scope, including remote working |
| Systems | The platforms, environments and supporting infrastructure included |
| People | Teams and functions bound by the ISMS policies |
| Exclusions | Anything left out, with a defensible reason |
How Osto fits an ISMS
An ISMS decides what should be controlled; the controls themselves still have to exist. Osto supplies the technical half: access management, endpoint protection, logging, vulnerability testing and cloud posture, with evidence mapped to ISO 27001 and more than 200 other frameworks. The policies, risk decisions and management review remain yours, because they describe how your organisation makes decisions.
Free security assessment
The controls an ISMS asks you to prove
Osto deploys the technical half of your management system and maps the evidence to ISO 27001 and 200+ frameworks.
Get a free security assessment Book a platform walkthroughEvidence from your own controls · 200+ frameworks · One platform, everything
Frequently asked questions
What does ISMS stand for?
ISMS stands for information security management system. It is the documented set of policies, processes, responsibilities and records an organisation uses to manage information security risk.
Is an ISMS the same as ISO 27001?
No. ISO 27001 is the standard that specifies what an ISMS must contain. The ISMS is the thing your organisation builds and runs. You can operate an ISMS without ever seeking certification.
Do we need software to run an ISMS?
No. An ISMS is a set of documented processes and records. Compliance platforms make the evidence easier to collect and keep current, but the management system itself is organisational rather than technical.
Who owns the ISMS?
Leadership owns it under Clause 5, which requires an approved policy, allocated resources and assigned responsibilities. Day-to-day operation is usually delegated, but accountability cannot be.

