Skip to content

Your glossary for risk and compliance

Helpful definitions of all of the terms you need to know to better manage risk and compliance.

ISO 27001
Cyber security

What is an Information Security Management System (ISMS)?

An Information Security Management System, also known as an ISMS, is a systematic approach consisting of processes, technology and people that helps you protect and manage your organisation’s information through effective risk management. It enables compliance with a range of standards, laws and regulations including IEC/ISO 27001, FedRAMP, SOC2, NIST CSF, and focuses on protecting three key aspects of information:

  1. Confidentiality: The information is not available or disclosed to unauthorised people, entities or processes.
  2. Integrity: The information is complete and accurate, and protected from corruption.
  3. Availability: The information is accessible and usable by authorised users.