Information Security Management System (ISMS)
An Information Security Management System, or ISMS, is a systematic approach to planning, implementing, monitoring and improving information security within an organisation. It comprises policies, processes, responsibilities and measures designed to protect information and IT systems. An ISMS is typically based on a structured assessment of information security risks, from which appropriate security controls are derived. It addresses technical, organisational and human aspects of security and supports the confidentiality, integrity and availability of information. ISO/IEC 27001 is a widely recognised international standard for establishing and operating an ISMS. Organisations use an ISMS to manage information security risks systematically, document security measures and continuously adapt their information security practices to changing requirements and threats.