🚨  NIS2 is now in effect. Security awareness is now legally required in the EU.

Check compliance
Log in
Back to Resource Center

What is an ISMS? The management system behind ISO 27001

An ISMS, short for information security management system, is the whole of policies, processes, roles and controls with which an organization deliberately manages its information security risks. It is how you decide what needs protecting, who is responsible, which measures apply and how you check whether any of it is working. The word system does the confusing here: an ISMS is a way of working, not a program you install.

That distinction matters more than it sounds, because it determines what you end up buying and what you end up building. Below we look at why the software misunderstanding is so persistent, what an ISMS actually consists of, how it relates to ISO 27001 and NEN 7510, how you set one up, and the part where most projects quietly stall.

An ISMS is not a piece of software

Search for ISMS and you will find plenty of tools promising to be one. They are useful, and a good tool saves real time on document control, risk registers and evidence collection. But the tool is the filing cabinet, not the system. An organization with an immaculate tool and no working processes has a very tidy record of things it is not actually doing.

The reason the confusion persists is that an ISMS is largely invisible. You cannot point at it the way you can point at a firewall. What you can point at are its outputs: a risk assessment that gets updated, a set of policies people actually follow, records of training, minutes of a management review, an internal audit that found something and led to a change. An auditor looks for exactly those traces, because they are the only evidence that the system is alive rather than written down.

What an ISMS actually consists of

The components below are common to virtually every framework, whether or not you pursue certification. Together they form a loop rather than a checklist: each part feeds the next, and the loop repeats.

  • Scope. Which parts of the organization, which locations, which systems and which information the system covers. A scope that is too broad stalls the project; one that is too narrow fails to cover the risk that matters.
  • Risk assessment and treatment. Identifying what could go wrong, how likely and how damaging it is, and deciding per risk whether you reduce, accept, transfer or avoid it. How to approach that in practice is covered in our guide to the ISO 27001 risk analysis.
  • Policies and procedures. The written rules on access, passwords, suppliers, incidents, devices and data handling. They only count when people can find them and recognize them from daily practice.
  • Roles and responsibilities. Who owns which risk, who approves exceptions, who reports what to management. Unassigned responsibility is the most common finding in any audit.
  • Controls. The concrete measures that reduce the risks you identified, technical and organizational alike.
  • Awareness and competence. Making sure the people in scope know what is expected of them and can demonstrate it. This is a requirement, not a nice extra.
  • Monitoring, internal audit and management review. Checking that measures work, that findings get followed up, and that leadership periodically looks at the whole thing and decides what changes.
  • Continual improvement. The Plan-Do-Check-Act cycle that keeps the system moving instead of freezing it at the moment of certification.

Looking for the awareness evidence your ISMS needs?

Guardey turns training, participation and progress into reporting you can put in front of an auditor for ISO 27001, NEN 7510 and NIS2.

Discover security awareness training

How an ISMS relates to ISO 27001 and NEN 7510

ISO 27001 is the international standard that sets out the requirements for an ISMS. That is the key point: the standard describes the management system, not a list of products. Its clauses cover the loop above, from scope and leadership through risk assessment to internal audit and management review. Certification means an external auditor has established that your system meets those requirements and functions in practice.

Alongside those clauses sits Annex A, a catalogue of controls you select from based on your own risk assessment, recording your choices and your reasoning in a statement of applicability. The guidance on implementing those controls lives in the companion standard ISO 27002, and the difference between the two is explained in our article on the difference between ISO 27001 and ISO 27002. You are not required to apply every control; you are required to justify your selection.

In Dutch healthcare the same idea appears as NEN 7510, which builds on the ISO structure and adds requirements specific to patient data. Organizations in scope of NIS2 will recognize the pattern too: the directive expects risk management measures and demonstrable training, which is precisely what a functioning ISMS produces as a by-product.

Setting up an ISMS in six steps

  1. Get leadership to commit, in writing and in budget. An ISMS assigns responsibilities across the organization. Without visible ownership at the top it becomes one person’s side project, and those do not survive contact with a busy quarter.
  2. Define the scope honestly. Write down what is in and what is out, and why. Excluding something is defensible; discovering an unnoticed gap during an audit is not.
  3. Do the risk assessment before choosing controls. The order matters. Controls chosen first and justified afterwards produce a system that protects what was convenient rather than what was risky.
  4. Write policies people can follow. Short, specific and matched to how the work actually happens. A policy that contradicts daily practice teaches employees that the rules are decorative.
  5. Train the people in scope and record it. Everyone needs to know the rules that apply to them, and you need to be able to show that they were trained and that it landed. Our ISO 27001 awareness training is built around that requirement.
  6. Audit, review, adjust. Run an internal audit, take the findings to a management review, and change something as a result. That last part is what an external auditor checks: not whether you found problems, but whether finding them changed anything. What such an audit involves is described in our piece on what an audit is.

Where most ISMS projects get stuck

Not on the technology, and rarely on the paperwork. Most organizations can write a policy set in a few weeks. The trouble starts at the point where the system has to reach people who never asked for it: the colleague who shares a login because the workaround is faster, the manager who approves an exception by chat, the new hire who never saw the onboarding module.

Auditors notice this quickly, because their questions are aimed at practice rather than documents. Not “do you have an access policy” but “show me how access was revoked for someone who left last month”. Not “do you train your staff” but “show me who was trained, on what, and what you did about the people who did not complete it”. If the answer is a signed attendance sheet from an annual session, the system is on paper only.

The organizations that get through this comfortably treat awareness as a running process rather than an annual event. Short, recurring training generates a continuous stream of records, keeps the rules present in people’s minds, and turns the awareness clause from a scramble before the audit into something that maintains itself.

How Guardey supports the human part of your ISMS

Guardey’s security awareness training covers exactly the part of an ISMS that is hardest to evidence: weekly challenges of about three minutes, gamification with leaderboards and streaks, and content that follows the current threat landscape. Employees train in the mobile app for iOS and Android or in the browser, so colleagues without a desk are included too.

For the ISMS itself, the reporting is the point. Participation, scores and progress per team are exportable as audit-ready evidence for ISO 27001, NEN 7510 and NIS2, and integrated phishing simulations show behaviour rather than attendance. Setup takes minutes, and more than 500 organizations work this way, including the European Parliament.

Frequently asked questions about an ISMS

Is an ISMS mandatory?

Not in itself. What is increasingly mandatory is the outcome: NIS2 expects appropriate risk management measures and demonstrable training, healthcare providers work to NEN 7510, and customers and insurers ask for evidence. An ISMS is the most established way to organize that, and certification is the way to prove it to outsiders.

Do you need ISO 27001 certification to have an ISMS?

No. Plenty of organizations run an ISMS along ISO lines without ever inviting an auditor, because they want the structure rather than the certificate. Certification becomes worthwhile when customers ask for it, when tenders require it, or when you need an external party to keep you honest.

How long does it take to set up an ISMS?

For a small organization with a clear scope, several months of part-time work is realistic before a first internal audit. What decides the timeline is rarely the writing; it is how quickly decisions get made about scope, risk acceptance and ownership.

Who should own the ISMS?

Someone with enough authority to make decisions stick, supported by the people who own the individual risks. Placing it entirely inside IT is a common mistake: much of an ISMS covers contracts, HR processes and supplier management, which is not where an IT team has any leverage.

An ISMS earns its keep the moment it changes a decision: a supplier who is asked a question that would not have been asked before, an exception that gets recorded instead of forgotten, a risk that gets an owner. Everything else, the documents, the tooling and eventually the certificate, is bookkeeping around that.

Want to see what auditable awareness reporting looks like?

In a 30-minute demo we show you the weekly challenges, the phishing simulations and the reports you can hand to your auditor.

Schedule a personal demo
Dinela Lokvancic
Dinela Lokvancic Marketing Specialist Dinela keeps Guardey's online presence up to date. She creates content that makes complex cyber security topics accessible, and helps organizations understand why security awareness training matters for their teams.
READY TO GET STARTED?

Join 500+ businesses already protecting their teams with Guardey

Start your free 14-day trial
14 days free · No credit card · Full access · Setup in 5 minutes
Or schedule a personalised demo