What is an ISMS and where do you start?
Information Security Management System — it sounds bigger than it is. For an SMB, it's a set of documents and routines, not a platform you install somewhere.
ISMS = Information Security Management System. In essence: your way of working on information security, documented and maintained. It is not software. It is how you think and act.
\n\nThe five building blocks
\n- \n
- Scope. What falls within your ISMS? The entire company, a specific business unit, only certain data? This is defined before you do anything else. \n
- Policy layer. 8–12 documents (security policy, access control, incident response, acceptable use, …). Around 40–80 pages in total. \n
- Risk management. A risk register covering risks, owner, measure, and residual risk. See risk management. \n
- Controls. The Annex A subset you implement. The Statement of Applicability (SoA) is your overview. \n
- PDCA cycle. Plan, Do, Check, Act. Sounds dramatic — in practice it means: reviews, audits, management review, lessons learned. \n
Where do you start?
\n- \n
- Define scope (1 day). \n
- Gap analysis against Annex A (1–3 days). \n
- Risk register, first version (2 days). \n
- Access control policy + A.9 (1 week through to evidence). \n
- Remaining policies (2–4 weeks, in parallel with gathering evidence). \n
The pitfall: perfection
\nYour ISMS does not need to be perfect. It needs to work and be demonstrable. Version 1 of your policies can be 80% there. Improvement is part of the PDCA cycle — it is entirely normal to update them every year.
\n\nSee also: ISO 27001 pillar, PDCA cycle explained.
Volledige gids: ISO 27001 para pymes sin gastar €50k en consultores
Dit artikel is onderdeel van onze uitgebreide Compliance-gids. Lees de pillar voor het complete plaatje.
Lees de pillar →