Glossary · OT cybersecurity
Information security management system (ISMS)
Also known as: ISMS
German: Informationssicherheitsmanagementsystem (ISMS)
In information security, an information security management system (ISMS) is the set of policies, processes, responsibilities and controls an organization uses to establish, implement, maintain and continually improve information security based on risk. ISO/IEC 27001 specifies the requirements for an ISMS.
- OT security
- Standards
In one sentence
An ISMS is an organization's risk-based system of policies, processes and controls for managing information security, specified in ISO/IEC 27001.
Example
A machine builder extends its ISO/IEC 27001 ISMS to cover the remote service platform through which it maintains customer machines.
Explained in context
Context cards connect this term with others to answer one question. Also in British English and German.
How it applies
- Organization: An ISMS defines scope, risk assessment method, controls (ISO/IEC 27002 gives guidance), responsibilities, internal audits and management review. Certification to ISO/IEC 27001 is voluntary but common.
- OT: A corporate ISMS often focuses on IT. For production, IEC 62443-2-1 describes the security program of the Asset owner; many companies integrate both so that OT is not left out of scope.
- Compliance: An ISMS helps organize the risk-management measures that NIS 2 Directive requires, but having one does not by itself show that all legal obligations are met.
- Documentation: ISMS policies, procedures and records are controlled documents. Documentation teams can contribute by keeping security procedures versioned, reviewed and findable, following Document control practice.
ISMS vs. IEC 62443
ISO/IEC 27001 is a management system standard for information security in general. IEC 62443 addresses industrial automation and control systems specifically, including technical requirements for systems and components.