Glossary
ISMS
Information Security Management System: an organisational framework and set of processes for managing information security systematically, often certified to ISO 27001.
An ISMS (Information Security Management System) is a set of policies, processes and controls designed to manage an organisation's information security in a structured, ongoing way.
ISMS and NIS 2
NIS 2 requires putting appropriate risk-management measures in place. An ISMS, particularly one certified to ISO 27001, is a recognised approach for meeting these requirements. It does not guarantee full NIS 2 compliance, but it covers a large part of it.
Key components
- Security policy: a framework document approved by management
- Risk analysis: identifying, assessing and treating risks
- Risk treatment plan: the measures implemented
- Management review: regular monitoring of the system's effectiveness
- Continuous improvement: the PDCA cycle (Plan-Do-Check-Act)
Link with ISO 27001
The ISO/IEC 27001 standard is the international certification benchmark for ISMSs. Certification demonstrates a recognised level of maturity in information security management, which can ease discussions with authorities under NIS 2.