What is an ISMS (information security management system)?
An ISMS (information security management system) is the set of policies, processes, and controls an organization uses to manage information security risk. ISO/IEC 27001 is the international standard that defines its requirements. An ISMS covers risk assessment, control selection, internal audit, and management review.
What the buyer is really asking
An ISMS (information security management system) is the ISO 27001 term for the policies, risk process, and review cycle that run your security program. If you are ISO certified, point to the certificate and scope. If you are not, describe the equivalent pieces you run and do not call them an ISMS.
Other ways buyers ask it
Every one of these wants the same answer:
- “How do you maintain your Information Security Management System?”
- “Is your ISMS certified to ISO 27001?”
- “What is the scope of your ISMS?”
Evidence to have ready
- ISO 27001 certificate and Statement of Applicability
- The ISMS scope statement
- Minutes from the most recent management review
How Tyrvar answers this
Tyrvar treats every wording above as one question. You write the answer once, attach the evidence, and revisit it when your setup changes. Each buyer gets that approved answer no matter how their questionnaire words it. If you have not answered it yet, Tyrvar flags the question for you and does not make something up. Try it on your own questionnaire.