ISMS Explained: The System ISO 27001 Certifies

ISMS explained: information security management system

An ISMS is the set of policies, processes and records an organisation uses to manage information security decisions, rather than the security tools themselves.

  • Glossary
  • Compliance

The short answer

An information security management system, or ISMS, is a documented way of running security: what you protect, who owns each decision, how risks are assessed, and how you check the arrangement still works. ISO 27001 certifies the management system, not the individual tools.

The word “system” misleads people. An ISMS is not software you install. It is closer to how a finance function works: written rules, named owners, a regular review, and records proving the rules were followed.

What an ISMS contains

Four things, and none of them is a product.

Scope and context

Which parts of the business, systems and locations are covered, and who the interested parties are.

Risk process

A repeatable method for identifying, analysing and treating information security risk, with named risk owners.

Controls and policies

The measures selected to treat those risks, and the written rules that govern them.

Leadership commitment

An approved policy, allocated resources and defined responsibilities, signed off at the top.

Monitoring and audit

Internal audits, measurement of whether controls work, and a management review at a set interval.

Improvement

A process for handling nonconformities, recording corrective action and feeding it back into the system.

How it operates

An ISMS runs as a loop rather than a project. ISO 27001 does not name the Plan-Do-Check-Act cycle in the 2022 edition, but the clause structure still follows it, and auditors look for evidence that the loop turned at least once before certification.

Plan Scope, risk criteria, risk assessment Do Implement controls and policies Check Internal audit and management review Act Correct findings, improve the system The cycle repeats. Certification checks that it has turned, not that security is finished.

Setting the scope

Scope is the first decision and the one that shapes cost. A narrow scope certifies less but completes faster. An unrealistically narrow scope, such as excluding the product that customers actually buy, gets challenged by the certification body and by buyers reading the certificate.

Scope elementWhat to state
Products and servicesWhich offerings are covered, named as customers would recognise them
LocationsOffices, data centres and cloud regions in scope, including remote working
SystemsThe platforms, environments and supporting infrastructure included
PeopleTeams and functions bound by the ISMS policies
ExclusionsAnything left out, with a defensible reason

How Osto fits an ISMS

An ISMS decides what should be controlled; the controls themselves still have to exist. Osto supplies the technical half: access management, endpoint protection, logging, vulnerability testing and cloud posture, with evidence mapped to ISO 27001 and more than 200 other frameworks. The policies, risk decisions and management review remain yours, because they describe how your organisation makes decisions.

Free security assessment

The controls an ISMS asks you to prove

Osto deploys the technical half of your management system and maps the evidence to ISO 27001 and 200+ frameworks.

Get a free security assessment Book a platform walkthrough

Evidence from your own controls · 200+ frameworks · One platform, everything

Frequently asked questions

What does ISMS stand for?

ISMS stands for information security management system. It is the documented set of policies, processes, responsibilities and records an organisation uses to manage information security risk.

Is an ISMS the same as ISO 27001?

No. ISO 27001 is the standard that specifies what an ISMS must contain. The ISMS is the thing your organisation builds and runs. You can operate an ISMS without ever seeking certification.

Do we need software to run an ISMS?

No. An ISMS is a set of documented processes and records. Compliance platforms make the evidence easier to collect and keep current, but the management system itself is organisational rather than technical.

Who owns the ISMS?

Leadership owns it under Clause 5, which requires an approved policy, allocated resources and assigned responsibilities. Day-to-day operation is usually delegated, but accountability cannot be.