ISMS voorbeeld

 

ISMS example

ISMS stands for Information Security Management System. So it is the management system to control your information security. The system includes the whole of policies, processes and measures to achieve this. Standards such as ISO 27001 and NEN 7510, the government baseline BIO or (upcoming) statutory regulation NIS2 contain requirements that such a management system must meet. An ISMS can be certified.

 

ISMS focus areas

To comply with the management system standards ISO27001 and NEN7510, an organization must have a complete management system (ISMS - Information Security Management System) with control measures with regard to information security. The focus areas are:

  • Security Policy
  • Asset management
  • Staff
  • Physical Security
  • Manage communication processes
  • management of operating processes
  • Access policy
  • Information systems
  • Incident management
  • Business continuity management
  • Compliance

And they are divided into the groups:

  • Organizational control measures
  • People-oriented management measures
  • Physical control measures
  • technological control measures

If you want to know more, please contact our business partners of Meta-audit.nl. Click here for their overview Mandatory documents ISO27001 / NEN7510.

Please note: the ISO 27001 has changed, ISO 27001:2022. And the same applies to NEN 7510: NEN 7510:2024.
Please note: the NIS2 directive (Network and Information Security directive) will be given a legal basis. With an ISO 27001 certificate or a NIS2 quality mark (QM10, QM20, QM30) you are in a strong position.
Our colleagues at Meta-audit.nl know more about it. Click here for their Quickstart implementation ISO 27001:2022 / NEN 7510:2024.
New: in collaboration with Meta-audit.nl an example ISMS (in accordance with ISO 27001:2022 or NEN 7510:2024) in the Metaware management system. So you can be on this ride in a few days ... :=)
Prepare a test system for this or  contact us for more information.

 

ISMS, control framework

The ISMS contains a large number of control measures that must be implemented. The whole of control measures is also called a control framework. 
These control measures must be clearly demonstrably effective and are therefore an important topic in any audit. A tool provides insight into the status of such a control framework. 


ISMS, step-by-step plan implementation

Setting up an ISMS is quite a job that requires a clear step-by-step plan for implementation, as well as good tooling.

The implementation is split into 5 phases:

  • Preparation
  • Structure of ISMS
  • Expansion of ISMS
  • Implementation of ISMS
  • Assessment, completion
     

ISMS, practical example

Even if you set up a management system as a cloud solution in 60 seconds , working step by step towards an implemented and certifiable ISMS requires the necessary attention. Below is an example of the basic setup of an ISMS using the Metaware platform. For the required 'controls' (measures), our business partner Meta-audit.nl with some overviews and the mandatory documents. (For their digital list, click here.) Their knowledge has been incorporated into the demo environments below.

 

 Metaware platform

 Characteristic

  • Fully integrated and modular platform for documents, risks, complaints, improvements, audits
  • Immediately deployable SAAS sovereign cloud software
  • Supports common standards for information security such as ISO 27001 and NEN 7510, NIS2

 Motivation

  • Overall picture of assurance versus realizations
  • Demonstrable compliance in a control framework
  • High audit efficiency

Decision factor

  • High ease of use through visual navigation and clear interfaces
  • Friendly licensing model based on core users

 

 

 

 

Start your free trial now

We don't have 'shiny leaflets'. Get behind the controls right away and experience the convenience, overview and productivity improvement.
We help you online and enrich you with the experience and best practices of other users.

Start Now