Skip to main content

ISO Management Systems

ISMS

An Information Security Management System. The set of policies, processes, risk decisions and records an organisation uses to manage information security, defined by ISO/IEC 27001. It is a management system rather than a technology, so it covers how decisions get made and evidenced, not only what is installed.

Why it matters: enterprise buyers ask for the certificate, and the certificate is issued against the system, not against your tooling.

Related terms

Questions about how this applies to you? Book a free 45 minute diagnostic.

Back to the glossary

We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.