What is an Information Security Management System according to ISO 27001?
What are the components of an ISMS?
An ISMS consists of clear documentation, regular risk analyses, and concrete protective measures. This includes instructions and process descriptions, risk assessments, and the implementation of a catalog of measures from Annex A of ISO 27001 to systematically protect your data and systems.
An information security management system follows the principle: data protection and IT security must not be left to chance. With an ISMS,
- organizations manage their information security requirements and set information security objectives,
- develop security policies for information security,
- issue work instructions,
- implement these in practice, and monitor whether they achieve their goals.
In doing so, they follow a logic that quality management according to ISO 9001 also follows: Plan, Do, Check, Act. Planning, acting, checking, and improving.

ISO 27001 specifies in Annex A which measures companies and organizations must implement as part of an information security management system. However, this catalog of measures is not exhaustive.
Organizations that align themselves with the BSI standard, for example, may implement different measures than those that strictly adhere to ISO 27001. In an information security management system, individual measures are developed and implemented for each company.
These measures are repeatedly reviewed and adapted in the event of changes (for example, new business processes and workflows).




