GRC Oversight
Glossary

ISMS

Information Security Management System: the overall management structure (policies, risk process, roles, continual improvement) that ISO 27001 certifies.

An ISMS is not a single document but a system: a risk assessment process, a set of policies, defined roles and responsibilities, and a cycle of internal audits and management review. ISO 27001 certification assesses whether your ISMS exists, is followed, and is improved over time, not just whether individual controls are checked off.

Looking for another term or the full list?