InfoSec

Information Security Management System (ISMS): Components, Structure and Value for Startups

What an ISMS is, what it consists of, and why startups should start earlier than they think.

Author
Andy Mura
Date
23.2.2026
Updated on
23.8.2026
Information Security Management System (ISMS): Components, Structure and Value for Startups

An information security management system, or ISMS, is a documented framework of policies, processes, roles and controls through which a company manages the protection of its information. For startups it is rarely a pure compliance exercise: the question about security documentation is now as standard in B2B sales conversations as questions about pricing or implementation timelines.

This guide explains what an ISMS is, which five components it consists of, what role the 93 controls in Annex A of ISO/IEC 27001 play, and where the difference lies between running an ISMS and holding a certification.

Key takeaways

  • An ISMS is a documented management system that protects three properties of information: confidentiality, integrity, and availability. It consists of five components: policies, risk assessment, controls, incident management, and continual improvement.
  • ISO/IEC 27001 sets out in clauses 4 to 10 what an ISMS has to deliver. Annex A lists 93 controls in four categories: 37 organizational, 8 people, 14 physical, and 34 technological.
  • You do not have to implement all 93 controls, but you do have to assess every one and justify its inclusion or exclusion. That justification lives in the Statement of Applicability, one of the mandatory documents in the certification audit.
  • The current version is ISO/IEC 27001:2022, Edition 3 from October 2022, extended by Amendment 1:2024 on climate action. Certificates issued against the 2013 version have been invalid since October 31, 2025.
  • An ISMS and a certification are not the same thing: the ISMS is the system you operate, the certification is the confirmation issued by an accredited certification body. A certificate is valid for three years, with surveillance audits in years one and two.

What is an ISMS?

An information security management system is a documented framework that defines how your company manages information security. ISO/IEC 27001 sets out in clauses 4 to 10 which requirements such a system has to meet, from determining the scope through the risk assessment to the management review.

What separates it from a collection of individual security measures is structure. A house built to a plan and a house that gained a room whenever somebody felt like it are both technically houses. Only one has foundations that hold. An ISMS supplies that plan: every policy, every control, and every procedure is tied to a stated objective and can be traced back to it.

What gets protected are three properties of information, often called the CIA triad. Confidentiality means only authorized people have access. Integrity means information stays accurate and unaltered. Availability means authorized people can reach it when they need to. Every measure in your ISMS ultimately serves one or more of those three goals.

CIA triad as the foundation of an information security management system: confidentiality, integrity and availability
CIA triad as the foundation of an information security management system

A common misconception: an ISMS is not software and not a folder of documents. Software can collect evidence and track deadlines, and documents are part of the system; the ISMS itself is the way your company makes decisions about information security. Buy a template pack, file it unchanged, and you have documents but no management system, and that is exactly the difference an auditor notices.

The second defining difference is the risk basis. Rather than implementing measures on instinct or reacting only after an incident, an ISMS requires you to name your own risks, assess their likelihood and impact, and select controls in proportion. Limited resources then land where they matter. How a running ISMS turns into a certificate, which audit stages are involved, and what the certificate actually states are covered in our guide to ISO 27001 certification.

Why startups need an ISMS

For startups, an ISMS often decides whether a deal closes at all. Enterprise procurement, investors, and partners ask early for demonstrable security practices, and the question rarely arrives at the end of the process.

The mistake many founders make: they treat information security as a topic for companies of 200 people and up. Headcount is not what determines sensitivity. A team of twelve can process payment data, store personal data subject to the GDPR, and hold credentials to customer systems. Your exposure follows what you manage.

Take a 45-person SaaS company bidding for an enterprise account. Procurement sends a security questionnaire with roughly 120 questions, legal wants a data processing agreement with an annex on technical and organizational measures, and IT security asks for the Statement of Applicability. Without an ISMS the founding team answers from memory, spread across two to three weeks, and every answer is an assertion. With an ISMS they are extracts from documents that already exist.

The second effect shows up as you grow. In the early days security runs on informal practice and tacit knowledge, and that approach breaks the moment you hire faster than you can explain. Documented access control policies, defined provisioning processes, and traceable training records are the difference between "someone talked the new colleague through it" and "the process ran and the evidence is on file".

A third argument gets overlooked: security decisions happen earlier. When information security sits inside the ISMS, a new tool, a new integration, or a new supplier is assessed before it goes live rather than repaired afterwards. That is cheaper, and it stops sloppy processes from setting hard over the years.

The five components of an ISMS

A working ISMS rests on five components that build on each other. Tick them off individually and you get documents. Keep them in order and you get a system.

Policies

Policies are the foundation. They set out which rules apply across the company, and they are the part of the ISMS most often lifted from the internet unchanged. A typical startup set is one overarching information security policy plus specific policies on acceptable use, access control, data classification, incident response, and supplier management.

What matters is that they match reality. If your acceptable use policy forbids something your team does daily, it is not strict, it is inert, and an auditor finds the gap in the first interview. Effective policies describe in plain language what people are actually meant to do, and name the consequences of not doing it.

Risk assessment and risk treatment

This is where the ISMS gets tailored to your company. You build an inventory of information assets: customer data, source code, financial and personnel data, intellectual property, and the systems that process all of it. For every significant asset you name realistic threat scenarios, assess likelihood and impact, and decide how to handle the risk.

You have four options: reduce the risk through controls, transfer it through insurance or contracts, avoid it by changing a practice, or knowingly accept it if it sits within your defined risk tolerance. ISO 27001 requires a documented methodology but does not prescribe which one. The output lives on in the risk register, which is maintained for the full life of the ISMS.

Controls

Controls are the concrete mechanisms that reduce risk: technical ones such as encryption and multi-factor authentication, physical ones such as access restrictions and device security, and organizational ones such as policies, training, and defined processes. Annex A of ISO/IEC 27001:2022 groups them into four categories.

Annex A categoryNumber of controlsReference range
Organizational controls37A.5.1 to A.5.37
People controls8A.6.1 to A.6.8
Physical controls14A.7.1 to A.7.14
Technological controls34A.8.1 to A.8.34
Total93A.5 to A.8

You do not have to implement all 93, but you do have to assess each one and justify any exclusion. Those justifications form the Statement of Applicability, which shows auditors that your selection is risk-based and traceable. Which control covers which requirement, and which eleven controls were added in 2022, is set out in our breakdown of all 93 Annex A controls.

Incident management

Even good security programs have incidents. The difference lies in the response. Your ISMS should define how security events are detected, how you assess whether an incident has occurred, how it is contained, eradicated, and recovered from, and how the lesson gets captured.

For a startup that does not mean running a security operations center around the clock. It means a written playbook, named roles, tested communication paths, and a deadline within which notification to authorities or customers is assessed. When the first significant incident arrives, that playbook decides whether the response is coordinated or improvised.

Continual improvement

An ISMS is not a project with an end date. The threat landscape changes, your company changes, and the system has to keep up with both. That means internal audits that check whether controls work as described, management reviews that judge the overall state, and a process for corrective action. ISO 27001 requires this cycle explicitly in clause 10.

ISMS and ISO 27001: where the difference lies

The ISMS is the system you build and operate. ISO/IEC 27001 is the international standard that defines what a credible ISMS looks like, and certification is the confirmation from an independent body that yours meets the requirements. You can run an ISMS without a certificate; without one you lack the proof that procurement departments want to see.

The standard requires a set of documented information. That list is the most practical entry point into the question of what an ISMS actually is on paper.

Documented informationClause of ISO/IEC 27001:2022
Scope of the ISMS4.3
Information security policy5.2
Information security risk assessment process6.1.2
Risk treatment process and Statement of Applicability6.1.3
Information security objectives6.2
Evidence of competence of the people involved7.2
Results of monitoring and measurement9.1
Internal audit programme and audit results9.2
Results of the management review9.3
Evidence of nonconformities and corrective actions10.2

The current version is ISO/IEC 27001:2022, Edition 3 from October 2022, extended by Amendment 1:2024, which adds climate action to clauses 4.2 and 6.1.2 and leaves Annex A untouched. The transition period from the 2013 version ended on October 31, 2025; certificates on the old basis have been invalid since. The current status of the standard is available in the official ISO listing.

A certificate is valid for three years. Surveillance audits follow in years one and two, with recertification in year three. How long the road there takes, and what the duration depends on, we have written up separately: how long an ISO 27001 certification takes.

The budget question is answered at the same level, broken down by company size and including the line items vendors usually leave out: the cost of ISO 27001 certification.

A cleanly built ISMS is also the foundation for further requirements. The GDPR requires appropriate technical and organizational measures under Article 32, plus accountability and documented processes, which is precisely the set of artifacts your ISMS produces anyway. The same holds for NIS2, although the overlap is not complete: which requirements you already cover with ISO 27001 and which gaps remain is set out in our comparison of where NIS2 and ISO 27001 overlap.

Three mistakes when building an ISMS

Adopting templates unchecked

Templates save time on wording, not on thinking. An adopted policy that does not describe how you actually operate produces exactly the nonconformity your internal audit will surface, and it surfaces before the external auditor arrives. Use the template as an outline and write the content against your own reality.

Drawing the scope too wide

A narrow, well-justified scope is not a sign of weakness. It is the most effective lever for keeping a first certification audit realistic, because audit time derives from the number of people in scope. For most startups the scope covers the core product and the infrastructure that carries it, not every part of the business.

Treating the ISMS as a project that ends with the certificate

After the certificate come the surveillance audits in years one and two. If nothing happens between certification and the first surveillance audit, no internal audit, no management review, no updated risk assessment, that is the single most common cause of findings the following year. Build the cycles into your normal operating rhythm instead of catching up before the audit date.

How Kertos supports building an ISMS

Kertos is a European compliance platform that brings the ISMS build into one system: risk register and risk treatment, the mapping of Annex A controls including the Statement of Applicability, policies with approval and version status, employee training, and automated evidence collection from your existing systems. What otherwise sits spread across spreadsheets, a wiki, and several tools hangs on one set of data.

The second part is the expert support. Kertos customers work with certified experts who help define the scope, review the risk assessment, and read through before the audit. That is where building an ISMS differs from rolling out software: the decisions stay yours, but you do not make them alone. What that looks like in the product is shown on the ISMS module of the Kertos platform.

In reviews, customers most often single out how far the build of the management system itself is carried:

"Kertos makes building an Information Security Management System incredibly smooth and intuitive."

Konrad E., review on G2

If you want to know where your company stands today, a gap analysis is the quickest way in. It shows which requirements are already met, which are open, and in what order they are sensibly worked through. Book a gap analysis.

ISMS as the shared basis for ISO 27001 certification and GDPR compliance

Frequently asked questions

What is an ISMS in simple terms?

An ISMS is the way a company manages information security: the policies that apply, the processes that get followed, the controls that are implemented, the people who are accountable, and the mechanisms that monitor and improve the whole thing. Instead of handling security problems as they arise, you decide in advance what gets protected and how.

Is an ISMS a legal requirement?

ISO/IEC 27001 itself is a voluntary standard, and no law requires an ISMS by name. The outcomes are what is mandatory: the GDPR requires appropriate technical and organizational measures under Article 32, and NIS2 obliges in-scope companies to take risk management measures under Article 21. An ISMS is the established way to meet those duties demonstrably, but it is not the only permissible one.

What is the difference between an ISMS and ISO 27001?

The ISMS is your own management system, ISO 27001 is the standard it gets measured against. You can operate an ISMS without being certified. Without certification, though, you lack the confirmation from an independent third party that your practice meets internationally recognized requirements, and that is exactly what enterprise procurement asks for.

Can a 15-person startup run an ISMS?

Yes. ISO 27001 scales with the size of the scope, not with a minimum company size. A team of 15 usually has a manageable system landscape, fewer processes, and shorter decision paths than a 500-person company; implementation is therefore less complex, not less feasible. What changes is the volume of documentation, not the requirement.

Does an ISMS have to implement all 93 Annex A controls?

No. You have to consider all 93 controls, but only implement the ones that match your risks. For every included and every excluded control you record the justification in the Statement of Applicability. In practice most companies select 60 to 80 of the 93; the selection has to match the risk assessment and be explainable in the audit.

The Founder's Guide about NIS2: Prepare your company Now before

Protect your startup: Discover how NIS2 can impact your business and what you need to consider now. Read the free white paper now!

Ready, your compliance to put on autopilot?
Andy Mura

Andy Mura

Head of Marketing

Andy Mura is Head of Marketing at Kertos, where he leads growth strategy for the company's compliance automation platform. A marketer and growth strategist by trade, he has spent years working in highly regulated industries such as payments, which is where his interest in compliance, data privacy, and information security first took root. That foundation has since been sharpened by extensive field research and by ongoing conversations with the CISOs and IT security leaders Kertos serves as customers. He writes about the practical realities of building and running security and compliance programs, drawing on what practitioners tell him works and what does not.

About Kertos

Kertos is the modern backbone of the data protection and compliance activities of scaling companies. We enable our customers to implement integrated data protection and information security processes in accordance with GDPR, ISO 27001, TISAX®, SOC2 and many other standards quickly and cheaply through automation.

Ready to simplify GDPR compliance?

CTA Image

📅 Schedule Your 5min Compliance Check

Please enter your business email to continue. We require a company email address to ensure we can best serve your organization.

📞 5min Compliance Check