Cybersecurity & resilience

ISMS (information security management system)

Published Reviewed

An information security management system is the governed set of policies, processes, roles, and controls through which an organisation manages information security risk continuously — the core of ISO/IEC 27001. It is a management loop, not a technology stack: risk assessment drives control selection, controls produce evidence, and management review drives improvement. Certification audits examine the loop, not just the controls.

Läs definitionen på svenska: LIS (ledningssystem för informationssäkerhet)

Also known as: Information security management system

Where this term does its work

This definition is general information, not legal advice. Always verify the current official source.