Information Security Management System (ISMS)
As the name suggests, a set of policies concerned with information security management. The idiom arises primarily out of
ISO/IEC 27001.
The key concept of ISMS is for an organization to design, implement and maintain a coherent suite of processes and systems for
effectively managing information accessibility, thus ensuring the confidentiality, integrity and availability of information assets
and minimizing information security risks.
As with all management processes, an ISMS must remain effective and efficient in the long term, adapting to changes in the internal
organization and external environment.
ISO/IEC 27001 therefore incorporates the typical "Plan-Do-Check-Act" (PDCA) approach to continuous improvement:
| Plan: | designing the ISMS, assessing information security risks and selecting controls | |
|---|---|---|
| Do: | implementing and operating the controls | |
| Check: | reviewing and evaluating performance of the ISMS | |
| Act: | changes made where necessary to bring the ISMS back to peak performance |
