ISMS: understanding the information security management system
Definition, ISO 27001:2022, the PDCA cycle, Annex A, implementation steps, mandatory documents and certification: the complete guide to the ISMS.
An ISMS (information security management system) is the organised set of policies, roles, processes and controls that allows an organisation to protect its information over time, starting from its risks. Its requirements are set by ISO/IEC 27001, the only standard in the ISO 27000 family that can be certified against. This guide explains what an ISMS is, how to implement it step by step, which documents it requires and how certification works.
ISMS: definition and objectives
A management system, not a technical project
The key word is management. An ISMS is not a firewall, a piece of software or a binder of procedures: it is a way of organising security so that it is decided, applied, checked and improved continuously. It answers three simple questions: what must be protected, and against what? Who does what to protect it? How do we know it works?
Its aim is to preserve the confidentiality, integrity and availability of information by applying a risk management process, and to give interested parties (customers, authorities, partners) confidence that risks are adequately managed. That is how ISO/IEC 27001 describes its purpose.
What an ISMS is not
- Not a security policy. The information security policy sets the rules; the ISMS is the system that keeps them alive.
- Not a certification. You can have an ISMS without certifying it; certification only attests that it meets the standard's requirements.
- Not a one-off project. An ISMS that is no longer reviewed or audited stops being one.
The ISMS and ISO 27001:2022
The current version is ISO/IEC 27001:2022, published in October 2022 and supplemented by a 2024 amendment requiring organisations to determine whether climate change is a relevant issue. Certificates issued against the old 2013 version had to be transitioned to the 2022 version by 31 October 2025, under the timeline set by the IAF (document MD 26). In 2026, a certified ISMS is therefore certified against the 2022 version.
Like all recent management system standards, ISO 27001 follows a common structure (the "harmonised structure"): clauses 1 to 3 are introductory, and the requirements sit in clauses 4 to 10.
| Clause | Title | What it asks for, in plain words |
|---|---|---|
| 4 | Context of the organisation | Understand issues and interested parties, and set the ISMS scope |
| 5 | Leadership | Management commitment, security policy, roles and responsibilities |
| 6 | Planning | Assess and treat risks, set objectives, plan changes |
| 7 | Support | Resources, competence, awareness, communication, documentation |
| 8 | Operation | Run the processes and the risk treatment plan |
| 9 | Performance evaluation | Monitor, measure, audit internally, hold the management review |
| 10 | Improvement | Handle nonconformities, act and improve continually |
The standard relies on other texts in the same family: ISO/IEC 27002:2022 details the security controls, ISO/IEC 27005:2022 guides risk management (see our article on ISO 27005), and ISO/IEC 27006-1 governs certification bodies.
The ISMS PDCA cycle
To understand how the clauses fit together, people use the Deming wheel, or PDCA cycle: Plan, Do, Check, Act. The 2005 version of the standard presented it explicitly; since 2013, ISO 27001 no longer imposes it, but the logic is the same and it remains the best way to read an ISMS. Click on each phase:
Plan
What you do- Understand the context and the expectations of interested parties
- Set the ISMS scope
- Commit management and publish the policy
- Assess and treat risks, set objectives
- Scope (4.3)
- Information security policy (5.2)
- Risk assessment method and results
- Statement of Applicability and treatment plan (6.1.3)
Do
What you do- Allocate resources and competence
- Raise awareness and communicate
- Control documentation
- Implement the risk treatment plan
- Evidence of competence (7.2)
- Controlled documented information (7.5)
- Results of risk assessments and treatments (8.2, 8.3)
Check
What you do- Monitor and measure effectiveness
- Run internal audits
- Hold the management review
- Monitoring and measurement results (9.1)
- Internal audit programme and reports (9.2)
- Management review results (9.3)
Act
What you do- Handle nonconformities
- Take corrective action
- Continually improve the suitability and effectiveness of the ISMS
- Nonconformities and corrective actions (10.2)
Annex A: 93 controls and the Statement of Applicability
Annex A of ISO 27001:2022 is a catalogue of 93 security controls, grouped into four themes (compared with 114 controls in 14 chapters in the 2013 version). Eleven controls are new and reflect changes in threats and practices: threat intelligence, cloud security, data leakage prevention, secure coding…
- 5.7 Threat intelligence
- 5.23 Information security for use of cloud services
- 5.30 ICT readiness for business continuity
- 7.4 Physical security monitoring
- 8.9 Configuration management
- 8.10 Information deletion
- 8.11 Data masking
- 8.12 Data leakage prevention
- 8.16 Monitoring activities
- 8.23 Web filtering
- 8.28 Secure coding
A key point that is often misunderstood: Annex A is not a list to apply wholesale. Controls are selected based on the risk assessment; Annex A is then used as a checklist to make sure no necessary control has been overlooked. The result is recorded in the Statement of Applicability (SoA), which states for each control whether it is included, why, and whether it is implemented. Exclusions must be justified: it is one of the first documents an auditor reads.
Implementing an ISMS: the steps
Implementing an ISMS follows a logical order derived from the standard's clauses. Here is a ten-step path, with the relevant clause, the expected output and the most common pitfall for each step:
- Step 01 · Clause 5.1
Secure management commitment
Management appoints an ISMS owner, provides resources and commits to keeping security objectives compatible with the strategy.
- Step 02 · Clause 4.1 · 4.2
Analyse the context and interested parties
Identify internal and external issues (threats, regulations, customers, subcontractors) and what each interested party expects in terms of security.
- Step 03 · Clause 4.3
Define the scope
Choose the activities, sites, systems and interfaces covered. A well-chosen scope is one where the ISMS brings real value.
- Step 04 · Clause 5.2
Write the security policy
Set security principles and objectives, approved by management, then break them down into topic-specific policies.
- Step 05 · Clause 6.1.2 · 8.2
Assess risks
Identify, analyse and evaluate risks with a defined, repeatable method: ISO/IEC 27005, EBIOS Risk Manager or an in-house method.
- Step 06 · Clause 6.1.3 · 8.3
Treat risks and write the SoA
Choose controls, compare them with Annex A, justify each inclusion or exclusion, and have risk owners approve residual risks.
- Step 07 · Clause 7 · 8.1
Deploy controls and raise awareness
Implement the treatment plan, train key people, raise awareness among all staff and control documentation.
- Step 08 · Clause 9.1 · 9.2
Measure and audit
Track useful indicators and run an internal audit programme covering the whole scope before certification.
- Step 09 · Clause 9.3 · 10
Management review and improvement
Present results, gaps and changes in context to management; decide on actions and handle nonconformities.
- Step 10 · Clause ISO/IEC 27006-1
Pass the certification audit
An accredited body runs the audit in two stages (documentation review, then verification of implementation), followed by yearly surveillance audits.
How long does it take? It all depends on the scope, the starting maturity and the resources. One thing is certain: an ISMS must have been running for a while before the certification audit, because the auditor will check that internal audits, measurements and a management review have actually taken place. Several months is realistic, often more for a large organisation.
Who does what? The standard does not set an organisation chart, but requires roles to be assigned and communicated (clause 5.3). In practice, you almost always find top management committing and arbitrating, an ISMS manager (often the CISO) running the system, risk owners who approve treatment and accept residual risks, control owners in IT and business teams, and internal auditors independent of the activities they check. The DPO is involved as soon as personal data is in scope.
The heart of the work lies in steps 5 and 6: risk analysis. ISO 27001 does not impose a method, as long as it produces consistent, valid and comparable results. In France, many organisations use EBIOS Risk Manager, ANSSI's method, which can be run in a risk analysis tool, or ISO/IEC 27005.
Mandatory ISMS documents
ISO 27001 speaks of "documented information": some must be maintained (documents), some retained (records, in other words evidence). Here is what the standard explicitly requires:
| Clause | Document or record |
|---|---|
| 4.3 | ISMS scope |
| 5.2 | Information security policy |
| 6.1.2 | Risk assessment process |
| 6.1.3 | Risk treatment process, Statement of Applicability |
| 6.2 | Information security objectives |
| 7.2 | Evidence of competence |
| 7.5.1 | Documents the organisation deems necessary |
| 8.1 | Information showing processes are carried out as planned |
| 8.2 · 8.3 | Results of risk assessments and risk treatment |
| 9.1 | Monitoring and measurement results |
| 9.2 | Audit programme and internal audit results |
| 9.3 | Management review results |
| 10.2 | Nonconformities, actions taken and their results |
On top of this come the documents required by the Annex A controls you select: topic-specific policies, asset inventory, operating procedures, continuity plan… The right reflex: document what is needed for the ISMS to work and be proven, no more.
ISO 27001 certification of the ISMS
Certification is issued by an accredited certification body; in France, accreditation is granted by Cofrac. The process runs as follows:
- Initial audit in two stages: the first checks the design of the ISMS and its documentation, the second checks on site that the system is actually applied.
- Certificate valid for three years, once any major nonconformities have been closed.
- Surveillance audits every year during the cycle, then a recertification audit.
Certification remains voluntary but is sometimes required. That is the case for HDS certification of health data hosts in France, whose framework is based on ISO 27001. Customers also very often ask for it, in tenders or supplier security questionnaires.
Why implement an ISMS: the benefits
Beyond the certificate, a well-run ISMS brings concrete benefits:
- Clear priorities. Controls follow from the organisation's real risks, not from a generic list or the latest alert in the press.
- Involved management. The management review forces regular reporting on the state of security and arbitration, which makes it easier to obtain resources.
- Evidence on hand. The records required by the standard are the same ones customers, insurers and authorities ask for.
- A foundation for other requirements. NIS 2, DORA, HDS or your customers' contractual requirements rely on the same controls: the work done for the ISMS can be reused.
- A commercial advantage. ISO 27001 certification is a common language recognised internationally, which shortens security questionnaires and reassures in tenders.
ISMS, security policy, risk analysis and GRC: how it all fits
The ISMS is the centre of gravity of information security, but it does not stand alone. The security policy translates it into rules; risk analysis drives it; and GRC (governance, risk and compliance) extends the approach to other frameworks and to third parties.
This is especially true with European regulations. The NIS 2 Directive (read From NIS to NIS 2) and the DORA Regulation do not require ISO 27001 certification, but their governance, risk management and security requirements overlap widely with those of an ISMS. An organisation that already has an ISMS starts with a head start, provided it links frameworks together rather than reassessing everything.
This is where a tool becomes useful: an ISMS lives over time, and running it in spreadsheets turns every audit into a consolidation project. Phinasoft links risk assessment (ISO 27005 or EBIOS RM), compliance assessments with evidence, compliance campaigns by subsidiary or site, versioned frameworks and security policies, action plans and dashboards for the management review. Auditors can be invited to review results and record their findings. Certification itself is still issued by an accredited body. To see how this applies to your scope, you can request a demo.
Summary
A system, not a document
The ISMS organises roles, processes and security controls over time; ISO/IEC 27001:2022 sets its requirements, in clauses 4 to 10.
Risk at the centre
Risk assessment decides which of the 93 Annex A controls are selected, and the Statement of Applicability justifies each choice.
An improvement loop
Indicators, internal audits and the management review keep the wheel turning; certification, valid for three years, checks that it really does.
Frequently asked questions
What is an ISMS?
An ISMS, or information security management system, is the set of policies, processes, roles and controls an organisation puts in place to protect its information continuously, based on an assessment of its risks. Its requirements are defined by ISO/IEC 27001, against which it can be certified.
Is an ISMS mandatory?
Not as a general rule: ISO 27001 is a voluntary standard. Certification is, however, required in some cases, such as for health data hosting in France (HDS), and customers often ask for it in tenders. NIS 2 and DORA do not impose ISO 27001, but an ISMS helps a great deal in meeting their risk management requirements.
What is the difference between an ISMS and a security policy?
The information security policy is a document that sets the organisation's security rules. The ISMS is the system that keeps those rules alive: it assesses risks, implements controls, checks them and improves them. The security policy is one of the documents required by the ISMS (clause 5.2).
How long does it take to implement an ISMS?
It mainly depends on the size of the scope, the starting maturity and the resources available. It generally takes several months, often from six months to more than a year, for an ISMS to really work: certification requires internal audits and a management review to have already taken place.
What are the mandatory documents of an ISMS?
ISO/IEC 27001:2022 requires, among other things, the scope, the security policy, the risk assessment and treatment processes and their results, the Statement of Applicability, security objectives, evidence of competence, monitoring results, the internal audit programme and results, management review results, and nonconformities and corrective actions.
What is the difference between ISO 27001 and ISO 27002?
ISO/IEC 27001 sets the ISMS requirements and can be certified against; its Annex A lists 93 security controls. ISO/IEC 27002 is a guide that details each of these controls: purpose, implementation guidance and attributes. You cannot be certified against ISO 27002; you use it to apply the controls you have selected.
Sources (9)
- ISO — ISO/IEC 27001:2022, Information security management systems — Requirements
- ISO — ISO/IEC 27001:2022/Amd 1:2024, Climate action changes
- ISO — ISO/IEC 27002:2022, Information security controls
- ISO — ISO/IEC 27005:2022, Guidance on managing information security risks
- IAF — IAF MD 26:2023 (Issue 2), Transition requirements for ISO/IEC 27001:2022 (copy published by the Singapore Accreditation Council)
- COFRAC — French accreditation committee
- ANSSI — The EBIOS Risk Manager method
- EUR-Lex — Directive (EU) 2022/2555 (NIS 2)
- EUR-Lex — Regulation (EU) 2022/2554 (DORA)
A platform and service that adapt to you
Our platform is designed for fine-tuned configuration and broad adaptability to your needs.