Information Security Management Systems (ISMS) form part of an organization’s overall management system. Based on risk assessment, an ISMS covers a series of management activities including establishment, implementation, operation, monitoring, review, maintenance and continuous improvement of information security. It is a system through which an organization establishes information security policies and objectives within its overall scope or specific boundaries, together with the methods adopted to achieve such objectives.
The standard for Information Security Management Systems can effectively protect information resources and ensure the sound, orderly and sustainable development of informatization. As a management system standard in the field of information security, certification of the Information Security Management System demonstrates that an enterprise has put in place a set of scientific and effective management systems for protection.