ISO Management Systems
ISMS
An Information Security Management System. The set of policies, processes, risk decisions and records an organisation uses to manage information security, defined by ISO/IEC 27001. It is a management system rather than a technology, so it covers how decisions get made and evidenced, not only what is installed.
Why it matters: enterprise buyers ask for the certificate, and the certificate is issued against the system, not against your tooling.
Related terms
Questions about how this applies to you? Book a free 45 minute diagnostic.
