Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · OT cybersecurity

Information security management system (ISMS)

Also known as: ISMS

German: Informationssicherheitsmanagementsystem (ISMS)

In information security, an information security management system (ISMS) is the set of policies, processes, responsibilities and controls an organization uses to establish, implement, maintain and continually improve information security based on risk. ISO/IEC 27001 specifies the requirements for an ISMS.

  • OT security
  • Standards

In one sentence

An ISMS is an organization's risk-based system of policies, processes and controls for managing information security, specified in ISO/IEC 27001.

Example

A machine builder extends its ISO/IEC 27001 ISMS to cover the remote service platform through which it maintains customer machines.

Explained in context

Context cards connect this term with others to answer one question. Also in British English and German.

How it applies

  • Organization: An ISMS defines scope, risk assessment method, controls (ISO/IEC 27002 gives guidance), responsibilities, internal audits and management review. Certification to ISO/IEC 27001 is voluntary but common.
  • OT: A corporate ISMS often focuses on IT. For production, IEC 62443-2-1 describes the security program of the Asset owner; many companies integrate both so that OT is not left out of scope.
  • Compliance: An ISMS helps organize the risk-management measures that NIS 2 Directive requires, but having one does not by itself show that all legal obligations are met.
  • Documentation: ISMS policies, procedures and records are controlled documents. Documentation teams can contribute by keeping security procedures versioned, reviewed and findable, following Document control practice.

ISMS vs. IEC 62443

ISO/IEC 27001 is a management system standard for information security in general. IEC 62443 addresses industrial automation and control systems specifically, including technical requirements for systems and components.

By knowledge.aitechdoc.world · Published September 26, 2026 · Last reviewed

Source: ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements

Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Blog and are not part of any standard.

Seen a mistake? Send us a note!