Instiq
Chapter 3 · Security management & evaluation·v1.0.0·Updated 7/9/2026·~15 min

What's changed: Initial version

3.2ISMS and controls

Key points

Covers ISMS (Information Security Management System) as the organizational framework for information security management, the division of roles between JIS Q 27001, which defines requirements, and JIS Q 27002, which exemplifies controls, the three-tier structure of an information security policy—policy, standards, and procedures—the continuous-improvement PDCA cycle, and the Statement of Applicability produced for certification.

No matter how excellent individual technical controls (encryption, access control) are, security cannot be sustained without a mechanism for operating them consistently across the whole organization. ISMS systematizes that mechanism—"the organization's system for continuously managing and improving security." A Registered Information Security Specialist must go beyond memorizing standard clauses and correctly apply, in practice, "which standard defines what" and "what belongs at which tier of the policy."

3.2.1What is ISMS

  • ISMS (Information Security Management System) refers to the entire management mechanism by which an organization selects and implements controls based on risk assessment to protect its information assets, and continually reviews them. Its defining feature is that it is a framework for operating individual technical controls organizationally, not a technical control itself.
  • An organization pursuing ISMS certification conducts a risk assessment tailored to its own circumstances, selects the necessary controls, documents the rationale for applying or excluding each one, and undergoes assessment by a third-party certification body. Certification itself is not the goal; it is positioned as the foundation for a continuous improvement cycle.

3.2.2The division of roles between JIS Q 27001 and JIS Q 27002

  • JIS Q 27001 defines the requirements for an ISMS (corresponding to ISO/IEC 27001). It specifies the mandatory obligations—such as "the organization shall conduct a risk assessment" or "management shall review the effectiveness of the ISMS"—that serve as the pass/fail criteria in a certification audit.
  • JIS Q 27002 is a code of practice for controls (corresponding to ISO/IEC 27002). Where JIS Q 27001 requires "select controls," JIS Q 27002 illustrates and explains what concrete control options exist (access control, cryptography, physical security, etc.); it is not itself a certification requirement.
  • In practice: consult JIS Q 27001 to confirm "what must be done to pass certification," and consult JIS Q 27002 to consider "which concrete controls to actually implement." The two stand in a complementary relationship of requirements versus practice guidance.
Exam point

Most-tested: the distinction that "JIS Q 27001 = requirements (mandatory)" and "JIS Q 27002 = code of practice for controls (illustrative)." Note that when asked "non-conformance with which standard is cited in a certification audit," the answer is JIS Q 27001 (non-conformance with a requirement).

3.2.3The three tiers of an information security policy and PDCA

  • An information security policy is structured in three tiers: policy, standards, and procedures. The policy (basic policy) is the top-level declaration set by management, stating "why the organization pursues security" and its "basic stance"—a highly abstract document that changes least frequently.
  • Standards concretize the policy into criteria for "what and to what extent" to protect (e.g., passwords must be at least 12 characters, sensitive data must be encrypted). Procedures further concretize the standards into the lowest-tier documents defining "who, when, and how" to execute them (e.g., the steps for changing a password). Procedures are revised most frequently, in step with changes to operations or systems.
  • The PDCA cycle—Plan (ISMS planning, risk assessment) -> Do (implementing and operating controls) -> Check (verifying effectiveness via internal audit and management review) -> Act (corrective action, continuous improvement)—repeats continuously. An ISMS is not built once and left alone; effectiveness is sustained by continuing to turn this cycle.

Suppose an ISMS officer at a mid-sized company receives an internal-audit finding: "the standards for accessing internal systems from personal devices during telework have not been documented." The officer's first decision is where in the policy hierarchy this standard belongs. The abstract direction—whether to permit telework at all, and how much risk the organization tolerates—should already be covered in the policy, so what needs to be newly written here is the concrete standard: "personal devices must have organization-approved MDM (mobile device management) software installed," "multi-factor authentication is mandatory for internal system access." Further, enforcing that standard in practice requires building out procedures—"steps for installing the MDM software," "steps for configuring multi-factor authentication." A judgment about which controls to select is also needed here: consulting JIS Q 27002 for illustrative controls on mobile devices and remote work, the officer selects controls (MDM deployment, multi-factor authentication) that match the organization's own risk assessment result (the risk of data leakage via personal devices was analyzed as high), and reflects them in the Statement of Applicability required by JIS Q 27001. If any illustrated control is deliberately not adopted, the reason (e.g., an equivalent risk reduction is achieved via an alternative control) must also be recorded in the Statement of Applicability. This whole sequence corresponds to the Plan-through-Do portion of the PDCA cycle, with effectiveness reconfirmed at the next internal audit (Check) and corrected if needed (Act)—continuous improvement.

TierContentRevision frequency
PolicyBasic stance set by management (why the organization pursues security)Lowest
StandardsCriteria for what and to what extent to protectModerate
ProceduresWho, when, and how to executeHighest
Warning

Trap: "JIS Q 27002 serves as the pass/fail criteria for certification audits" is wrong—pass/fail is determined by the requirements in JIS Q 27001; JIS Q 27002 is merely a code of practice (illustrative reference) for controls. Also wrong: "the Statement of Applicability only needs to list the controls that were adopted"—it must also record controls that were not adopted, along with the reasons.

ISMS, 27001/27002, 3-tier policy, PDCA.
A framework for continual management

3.2.4Section summary

  • ISMS is the organizational mechanism for managing information security. JIS Q 27001 = requirements (mandatory), JIS Q 27002 = code of practice for controls (illustrative)
  • The policy has three tiers: policy (abstract, low-frequency) -> standards (what and to what extent) -> procedures (who, when, how)
  • Effectiveness is sustained by continually turning the PDCA cycle (Plan-Do-Check-Act), and the Statement of Applicability records adopted and non-adopted controls along with the reasons

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. During an ISMS certification audit, a non-conformance was cited on the grounds that "records of a risk assessment do not exist." Which standard's non-conformance does this correspond to?

Q2. An organization wants to newly establish the standard "personal devices used for telework must have organization-approved MDM software installed." At which tier of the information security policy should this standard most appropriately be documented?

Q3. In the PDCA cycle of an ISMS, which stage confirms the effectiveness of the ISMS through internal audits and management review?

Check your understandingPractice questions for Chapter 3: Security management & evaluation