Definition
An ISMS (Information Security Management System) is not a single product or control, but the whole of the policies, roles, responsibilities, risk assessments and procedures an organisation uses to manage information security systematically over time. ISO 27001International standard for information security management systems - provides framework for protecting sensitive information. is the standard that specifies which requirements an ISMS must meet to be certified - but the ISMS itself is what the organisation actually does every day: who has access to what, how deviations are handled, how supplier risk is assessed. An ISMS without certification can work well internally; a certification without a functioning ISMS is just paper.