You are on page 1of 1

What is an information

security management
System (ISMS)?

An ISMS is a It consists of people, It helps you make It protects data in all


system for managing processes and appropriate decisions its forms (not just
information security technology (it’s not about the risks that personal data).
effectively. all about IT!) are specific to your
business
environment.

It secures data in It must be led and Risk assessments are The risk assessment
various formats, supported by top central to the ISMS. results in a set of
including online leadership and actions (controls) to
information and involve everyone in treat, avoid, manage
paper-based data. the organisation. or reduce risks.

These controls are An ISMS requires The international ISO/IEC 27001 also
optimised according continual information security includes a set of
to your unique risk improvement management standard, 114 optional
environment and processes so that the ISO/IEC 27001, controls that can be
objectives. controls remain outlines the used to manage
effective. specifications for risks.
implementing an ISMS.

Achieving accredited certification demonstrates that you are Optional accredited


certification to
following information security best practice according to the
ISO/IEC 27001 provides
requirements of ISO/IEC 27001.
an independent

Find out about the benefits of implementing an assessment of your


information security
ISO 27001-compliant ISMS.
posture.

Find out how to get started with


implementing an ISMS today

You might also like