Back to glossary

ISMS

2 min read

In security governance, an ISMS (information security management system) is the framework of policies, processes and controls through which an organisation manages security risk continuously. It is the object that ISO 27001 certifies: the standard does not certify a checklist of controls, it certifies that you run a working management system around them.

July 29, 2026
Compartir:

How it works

An ISMS is a management system, in the same sense as a quality or environmental management system: a defined scope, a risk assessment, chosen controls, documented processes, and a cycle of monitoring and improvement. It starts from what the organisation is protecting (which is why an asset inventory is foundational), assesses the risks to those assets, selects controls to treat them, records that selection in a Statement of Applicability, and then operates a continual loop of measuring, reviewing and adjusting. ISO 27001 certifies this system: not that a fixed list of controls is present, but that the organisation runs a functioning process to identify and treat its risks over time.

What goes wrong

The common misunderstanding is that ISO 27001 is a control checklist, so teams implement Annex A controls and expect a certificate, missing that the standard is about the management system that decides, evidences and improves those controls. An ISMS that exists only as documents (a risk assessment written once, a Statement of Applicability never revisited) satisfies the paperwork and manages nothing. From a security standpoint the failure is a static system: risks are assessed at certification and never again, so the ISMS does not react as the estate and the threat change, and the controls it selected drift out of line with reality while the certificate remains valid.

Where this shows up in an audit

An ISMS needs a risk assessment grounded in what is actually exploitable, and technical testing supplies that input: a penetration test or red team turns assumed risks into measured ones and feeds the results into the risk treatment. The evidence also demonstrates that selected controls operate, which is what the management system and its certification require. We frame findings so they slot into the ISMS risk process and the obligations it may also serve, such as NIS2 or the ENS. This is part of how testing feeds an ISMS risk process.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.