Skip to content
CyberNIS2

Glossary

ISMS

Information Security Management System: an organisational framework and set of processes for managing information security systematically, often certified to ISO 27001.

An ISMS (Information Security Management System) is a set of policies, processes and controls designed to manage an organisation's information security in a structured, ongoing way.

ISMS and NIS 2

NIS 2 requires putting appropriate risk-management measures in place. An ISMS, particularly one certified to ISO 27001, is a recognised approach for meeting these requirements. It does not guarantee full NIS 2 compliance, but it covers a large part of it.

Key components

  • Security policy: a framework document approved by management
  • Risk analysis: identifying, assessing and treating risks
  • Risk treatment plan: the measures implemented
  • Management review: regular monitoring of the system's effectiveness
  • Continuous improvement: the PDCA cycle (Plan-Do-Check-Act)

The ISO/IEC 27001 standard is the international certification benchmark for ISMSs. Certification demonstrates a recognised level of maturity in information security management, which can ease discussions with authorities under NIS 2.