ISMS example
ISMS stands for Information Security Management System. So it is the management system to control your information security. The system includes the whole of policies, processes and measures to achieve this. Standards such as ISO 27001 and NEN 7510, the government baseline BIO or (upcoming) statutory regulation NIS2 contain requirements that such a management system must meet. An ISMS can be certified.
ISMS focus areas
To comply with the management system standards ISO27001 and NEN7510, an organization must have a complete management system (ISMS - Information Security Management System) with control measures with regard to information security. The focus areas are:
- Security Policy
- Asset management
- Staff
- Physical Security
- Manage communication processes
- management of operating processes
- Access policy
- Information systems
- Incident management
- Business continuity management
- Compliance
And they are divided into the groups:
- Organizational control measures
- People-oriented management measures
- Physical control measures
- technological control measures
If you want to know more, please contact our business partners of Meta-audit.nl. Click here for their overview Mandatory documents ISO27001 / NEN7510.
Please note: the ISO 27001 has changed, ISO 27001:2022. And the same applies to NEN 7510: NEN 7510:2024.
Please note: the NIS2 directive (Network and Information Security directive) will be given a legal basis. With an ISO 27001 certificate or a NIS2 quality mark (QM10, QM20, QM30) you are in a strong position.
Our colleagues at Meta-audit.nl know more about it. Click here for their Quickstart implementation ISO 27001:2022 / NEN 7510:2024.
New: in collaboration with Meta-audit.nl an example ISMS (in accordance with ISO 27001:2022 or NEN 7510:2024) in the Metaware management system. So you can be on this ride in a few days ... :=)
Prepare a test system for this or contact us for more information.
ISMS, control framework
The ISMS contains a large number of control measures that must be implemented. The whole of control measures is also called a control framework.
These control measures must be clearly demonstrably effective and are therefore an important topic in any audit. A tool provides insight into the status of such a control framework.
ISMS, step-by-step plan implementation
Setting up an ISMS is quite a job that requires a clear step-by-step plan for implementation, as well as good tooling.
The implementation is split into 5 phases:
- Preparation
- Structure of ISMS
- Expansion of ISMS
- Implementation of ISMS
- Assessment, completion

ISMS, practical example
Even if you set up a management system as a cloud solution in 60 seconds , working step by step towards an implemented and certifiable ISMS requires the necessary attention. Below is an example of the basic setup of an ISMS using the Metaware platform. For the required 'controls' (measures), our business partner Meta-audit.nl with some overviews and the mandatory documents. (For their digital list, click here.) Their knowledge has been incorporated into the demo environments below.
|
Metaware platform
Characteristic
- Fully integrated and modular platform for documents, risks, complaints, improvements, audits
- Immediately deployable SAAS sovereign cloud software
- Supports common standards for information security such as ISO 27001 and NEN 7510, NIS2
Motivation
- Overall picture of assurance versus realizations
- Demonstrable compliance in a control framework
- High audit efficiency
Decision factor
- High ease of use through visual navigation and clear interfaces
- Friendly licensing model based on core users
|
