Skip to content

What an ISMS is, and why a spreadsheet stops at the second standard

4 min read Last checked on

An ISMS is the standing way of working with which an organisation decides which information it protects, which risks come with it, which controls it applies and how it shows that they work. ISO 27001 sets out the requirements for such a system in clauses 4 to 10. An ISMS is neither a document nor a tool.

An ISMS is neither a document nor a tool. It is the way an organisation decides what it protects, who decides about it, which controls it applies and how it shows that those controls do what they should. An auditor does not look at separate policy documents, but at how they fit together.

What an ISMS is made of

Every ISMS revolves around the same questions, whatever the size of the organisation:

  • Scope. Which parts of the organisation, which services and which locations it covers.
  • Risks. What can go wrong with the information within that scope, how likely that is and what the consequences are.
  • Controls. What the organisation does to reduce those risks, and why it does not apply certain controls.
  • Evidence. Records that show the controls are actually carried out.
  • Review and improvement. Internal audits, a management review and the follow up of what comes out of them.

Those parts depend on each other. A risk leads to a control, a control produces evidence, an audit tests that evidence, and a nonconformity leads to an improvement that touches the risk again.

What ISO 27001 asks of an ISMS

ISO 27001 describes the requirements for an ISMS in clauses 4 to 10. In plain language, without reproducing the standard:

Clause Subject What it means in practice
4 Context Knowing who you are, who has a stake in your security and what falls within scope.
5 Leadership Management carries the ISMS, sets the policy and assigns roles.
6 Planning Assessing and treating risks, and choosing measurable objectives.
7 Support People, competence, awareness, communication and controlled documentation.
8 Operation Doing what was planned, and reassessing risks when something changes.
9 Performance evaluation Measuring, carrying out internal audits and holding the management review.
10 Improvement Resolving nonconformities and making the system work better over time.

The standard also contains an annex of controls, Annex A. Which of those apply and why is recorded by the organisation in its Statement of Applicability.

The same clause structure returns in other management system standards, such as NEN 7510 and ISO 9001. That is deliberate: they all follow a shared structure known as Annex SL.

Where a spreadsheet is good enough

For one standard, a small scope and a stable group of people, a spreadsheet with a folder of documents can work. Many organisations obtain their first ISO 27001 certificate that way. It works as long as one person keeps the overview and holds the connections in their head.

Where it breaks at the second standard

A second standard changes the question. An IT provider in healthcare that carries NEN 7510 alongside ISO 27001 has largely the same controls, but two sets of requirements those controls must satisfy.

In a spreadsheet this produces two tabs with nearly the same rows. Evidence is supplied twice, or updated in one place and not in the other. A change to a risk has to be made in two places. After a year the two tabs contradict each other, and that is the first thing an auditor notices.

The problem is not the spreadsheet itself. The problem is that the connections between risk, control, requirement and evidence are not recorded anywhere, except in the head of the person who maintains it.

What is needed instead

What the second standard asks for is one place where a control exists once and points to every requirement it covers. Evidence is supplied once and counts wherever it applies. A change to a risk is immediately visible at every control and every standard connected to it.

That can be done with discipline in a spreadsheet, with an ISMS tool, or with a management system that treats the standards as projections of one core. Trustbird is built around that last idea. Whatever form you choose, the way of working stays with the organisation: a tool keeps the records, the ISMS is what people do with them.

Frequently asked questions

What does ISMS stand for?

Information security management system. It is the way of working with which an organisation plans, carries out, checks and improves its information security.

Is an ISMS the same as ISO 27001?

No. ISO 27001 is the standard that describes what an ISMS must meet. The ISMS is what an organisation actually puts in place. A certification body assesses whether that ISMS meets the standard.

Is an ISMS a software package?

No. An ISMS is a way of working made up of agreements, roles and records. Software can store those records and connect them, but it does not replace the way of working.

Does a small company need an ISMS?

If it wants to obtain or keep an ISO 27001 certificate, yes. The size of the organisation changes how extensive the ISMS is, not whether it is needed.

When is a spreadsheet no longer enough?

Usually at the second standard. The same control then has to satisfy two sets of requirements, and the evidence has to hold up in two places. Separate tabs drift apart.

Read next

Sources

  1. ISO, ISO/IEC 27001 Information security management systems
  2. NEN, information security and standards

Trustbird is being built with two certified design partners, and we are looking for more companies to join them at co-founder pricing.

Become a design partner