What's changed: Initial version
2.2ISMS and Information Security Policy
Learn about the ISMS (information security management system), the international standard ISO/IEC 27001, the operating cycle PDCA, the three-tier structure of information security policy, standards, and procedures, the Statement of Applicability (SoA) prepared for certification, and the meaning of ISMS certification.
Simply piling up ad hoc risk treatments one at a time cannot sustain an organization-wide level of security. Building an ISMS as a mechanism for ongoing management and running the PDCA cycle in line with the international standard ISO/IEC 27001 creates a system that keeps revisiting security measures as risks and the business environment change. Correctly understanding the hierarchical structure of documents topped by the policy is also directly relevant to practical understanding for SG.
2.2.1ISMS and ISO/IEC 27001
- ISMS (Information Security Management System) refers to the whole mechanism by which an organization continuously manages everything from setting policy through operation and review, in order to maintain the confidentiality, integrity, and availability of its information assets. Its distinguishing feature is that it is kept running as a management system, not a one-off control deployment.
- ISO/IEC 27001 is the international standard that defines the requirements for an ISMS. Obtaining ISMS certification (ISO/IEC 27001 certification), in which a third-party body audits and certifies conformance to this standard, lets an organization demonstrate objective proof of trustworthiness to business partners and users. Because certification can be scoped to a specific set of information assets, departments, or sites (the scope of application), checking how far the certified scope actually extends matters in practice.
2.2.2The PDCA cycle
- PDCA is the operating cycle of repeating Plan -> Do -> Check -> Act. In an ISMS, Plan sets policy and controls based on risk assessment, Do deploys and operates the controls, Check inspects operations via internal audits and monitoring, and Act corrects problems found and feeds them into the next Plan.
- The point of PDCA is that, because the threats surrounding information security and the nature of the business keep changing, the premise is continuous improvement based on inspection results, rather than operating a fixed set of measures set up once. Skipping Check and jumping straight from one Do to the next (operating without inspection) is a classic mistake that runs counter to the purpose of an ISMS.
The staples: an ISMS is the mechanism for ongoing management, and ISO/IEC 27001 is the international standard defining its requirements; PDCA repeats in the order Plan -> Do -> Check -> Act; the document hierarchy is policy (top level, approved by management) -> standards (rules by area) -> procedures (concrete work steps); the Statement of Applicability (SoA) documents which controls were adopted and why. A classic wrong-answer pattern is confusing the order of the document hierarchy (such as reversing standards and procedures).
2.2.3The three tiers: policy, standards, and procedures
- Information security policy is the top-level document, approved by management, that states the organization's basic stance and objectives on information security. It is highly abstract, declaring "why" the organization pursues information security, and is not revised frequently.
- Standards are the concrete rules set per area to realize the policy (for example, "passwords must be at least 12 characters" or "important data must be stored encrypted"). Procedures are the concrete work steps for carrying out the standards on the ground (for example, "the steps for the password-change screen" or "the setup steps for encryption software"). Understand this as a staged progression from abstract to concrete: policy is "what we aim for," standards are "what must be done," and procedures are "how to do it."
- The Statement of Applicability (SoA) is a document that specifies, from the annex (list of controls) of ISO/IEC 27001, which controls the organization has adopted and why, and the reasons for any controls it has chosen not to adopt. In an ISMS certification audit, consistency between the risk assessment results and the Statement of Applicability is checked.
Take an IT company's path toward obtaining ISMS certification as an example of how the document hierarchy connects to PDCA. First, management approves and publishes an information security policy stating, "our company will appropriately protect the information assets entrusted to us by customers, and will strive for business continuity and trust." To realize this policy, the information systems department develops standards by area. For example, an "access management standard" sets a concrete rule: "grant only the privileges necessary for the job, and promptly remove privileges upon resignation or transfer." Further, for staff on the ground, procedures are created to carry out this standard: "how to fill in the account-issuance request form" and "the steps for removing a departing employee's privileges in coordination with HR transfer information." This whole body of work corresponds to PDCA's Plan. Next, in the Do stage, accounts are actually managed following these procedures. Some months later, in the Check stage, an internal audit finds a deficiency: for some departing employees, account deletion was delayed by several days. In the Act stage, the cause of this deficiency (a lag in the timing of HR transfer-information linkage) is analyzed, and the procedure is revised to "delete accounts the same day via automatic linkage with the HR system," feeding into the next Plan. In parallel, in preparation for the ISMS certification audit, the company organizes, from the list of controls in ISO/IEC 27001, which controls it adopted based on its own risk assessment results (such as "access control" and "encryption") versus which it chose not to adopt because they do not apply to its business (such as "requirements for a specific cryptographic algorithm"), together with the reasons, into a Statement of Applicability. The auditor cross-checks this Statement of Applicability against the risk assessment results and the actual operating records (evidence of Check and Act), and certification is granted if no problems are found.
| Tier | Content | |
|---|---|---|
| Policy | Basic stance/objectives (top level, approved by management) | "Appropriately protect information assets" |
| Standards | Concrete rules by area | "Passwords must be at least 12 characters" |
| Procedures | Concrete work steps on the ground | "Steps for the password-change screen" |
Trap: "standards are the concrete operating manual used by staff on the ground" is wrong. The concrete operating steps used on the ground are procedures; standards are rules set per area, one level more abstract than procedures. Also, "obtaining ISMS certification means information security incidents will no longer occur within the organization" is wrong--certification proves that the management mechanism conforms to the standard, not that incidents are guaranteed to never occur. Furthermore, "if Check finds no problems, Act is unnecessary" is wrong--Act is the heart of continuous improvement, a stage where feeding results into the next Plan (including simply maintaining course) is considered regardless of whether problems were found.
2.2.4Section summary
- ISMS is the whole mechanism of ongoing management; ISO/IEC 27001 is the international standard defining its requirements. PDCA repeats Plan -> Do -> Check -> Act for continuous improvement
- Document hierarchy = policy (top level, management-approved) -> standards (rules by area) -> procedures (work steps on the ground)
- Statement of Applicability (SoA) documents adopted/non-adopted controls and the reasons. ISMS certification proves the management mechanism conforms to the standard, not that incidents are guaranteed never to occur
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. The information systems department documented "the concrete operating steps for the password-change screen." Which tier of the information security document hierarchy does this correspond to?
Q2. An organization operating an ISMS finds, through an internal audit, a deficiency in which account deletion was delayed. After analyzing the cause, it revises the procedure and feeds the change into the next plan. Which stage of PDCA does this series of activities correspond to?
Q3. In preparation for an ISMS certification audit, an organization wants to organize and document, from the list of controls in ISO/IEC 27001, which controls it adopts and why, and the reasons for controls it did not adopt. Which document is most appropriate to create?

