Skip to content

Instantly share code, notes, and snippets.

@kasia-kittel
Created March 31, 2016 10:21
Show Gist options
  • Select an option

  • Save kasia-kittel/9e76bf423112fa4aebc937a88acaf7e0 to your computer and use it in GitHub Desktop.

Select an option

Save kasia-kittel/9e76bf423112fa4aebc937a88acaf7e0 to your computer and use it in GitHub Desktop.
Short information about Information Security Management Systems

Information Security Management System

Short definition

Systematic and structural approach / framework to manage sensitive information (i.e. customer data, financial information, intellectual property, employee details or information entrusted to them by third parties) so it reminds secure.

This is usually ensured by designing, implementing and maintaining a set of policies, processes and systems to manage risks related to all IT assets.

These policies, processes and systems should be applied to business, organisational and technical levels.

To assure ISMS accuracy it should be based on one of the information security standards like ISO27000:2005 or Common Criteria and shaped by the organisation's needs and objectives.

Beyond technical level the ISMS should imply:

  • business continuity
  • improve organisation image (credibility and trust)
  • legal compliance
  • rises awareness for information security risks

External sources

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment