What is an ISMS?
An ISMS (Information Security Management System) is a way of working: policies, risk analysis, security measures, and compliance monitoring that together determine how an organization handles information security. The word "system" refers to this methodology, not to an IT system. It is therefore not a software package or a standalone piece of technology.
An ISMS consists of several core components: an information security policy, a risk analysis with corresponding risk treatment, concrete security measures, employee awareness, and continuous monitoring. The difference between this and isolated measures lies in that cohesion. A firewall and a password policy do not constitute an ISMS; they are individual components that only form an ISMS when they fall under the same policy, the same risk analysis, and the same improvement cycle.
Furthermore, an ISMS never automatically applies to the entire organization. Before the first risk analysis begins, you must define the scope: which departments, locations, systems, and data are covered. An ISMS that only covers the IT department while customer data is also held by customer service and external suppliers misses exactly the risks that matter most.
Why does an organization need an ISMS?
Without an ISMS, information security is often reactive: a measure taken after an incident, a policy no one remembers, or a risk analysis that was last updated three years ago. An ISMS reverses this order. Risks are identified in advance, measures follow from that, and the cycle is repeated as soon as the organization, the threats, or the technology change.
For organizations subject to the Cyber Security Act, there is an additional legal reason. The Cyber Security Act (Cbw), the Dutch implementation of NIS2, came into effect on August 15, 2026, and applies to organizations within 18 sectors. The law requires these organizations, among other things, to manage cyber risks and take appropriate and proportionate security measures. The NCSC therefore cites an ISMS as the starting point for providing structure to information security and keeping risks manageable.
In addition, there is a commercial reason. In tenders and supplier assessments, demonstrable information security, for example through an ISMS or ISO 27001 certification, can be a selection criterion or a requirement.
Setting up an ISMS with the four-step PDCA cycle
Implementing an ISMS basically follows four steps, which you then continue to repeat.
Plan: first determine the context and scope and establish the policy. Then, conduct a risk analysis. A practical way to clearly formulate a risk scenario is by using four elements: a threat, an asset, a method by which the threat occurs, and an impact on the organization. For those who do not want to start from scratch, you can use the free scenario builder from Polar Risk to create scenarios according to this structure.
Do: implement the measures. Translate the risk analysis into concrete security measures, access management, procedures, and training. Define who is responsible for what.
Check: monitor and audit. Measure whether the measures are working through internal audits, incident logging, and periodic management reviews. Without measurement, no one knows if the ISMS is delivering results.
Act: adjust. Revise policies and measures based on the findings from the check phase, and restart the cycle. An ISMS that is left untouched after the first PDCA round is just a snapshot rather than a system.
ISMS and ISO 27001: what is the difference?
ISO 27001 is the international standard that sets requirements for an ISMS with which an organization systematically manages information security risks and protects the confidentiality, integrity, and availability of information. You can also have your organization certified to demonstrate that you comply with the ISO 27001 standard. The official ISO 27001 contains 93 control measures in its appendix (Annex A), divided into four domains: organizational, people, physical, and technological.
Those 93 measures are not a checklist. Annex A is a reference framework from which an organization indicates which ones are applicable to them, documented in a Statement of Applicability.
The biggest pitfall: a compliance-driven instead of a risk-driven ISMS
The most common mistake when setting up an ISMS is making it compliance-driven rather than risk-driven. Annex A of ISO 27001 describes 93 control measures, and many organizations try to implement and document them one by one, regardless of whether they address a significant risk.
The result is a growing pile of policy documents, procedures, and evidence that primarily prove that something has been recorded. Every measure is assigned an owner, a review date, and a file, while the risk analysis often remains superficial. The organization is busy with the ISMS, not with the risks that the ISMS is supposed to manage.
That is a costly mistake. 40% of professionals cite budget shortages as a bottleneck in information security (CompTIA, 2025). An ISMS that spends too much time on a control measure for a negligible risk is misallocating that scarce budget. Annex A describes what types of measures can be relevant, not how much attention each measure deserves. That assessment requires knowing what the risk is and, more importantly, how significant it is.
Compliance-driven work also consumes time and attention from the business itself: collecting evidence, drafting documents, and obtaining approvals for measures that no one outside of security can explain the necessity of. That time is taken away from regular work. Without a clear explanation of the importance, support for the ISMS decreases as a result.
From compliance-driven to risk-driven: identifying risks comes first
Effective risk identification and assessment is one of the most critical steps in an ISMS. It determines which risks are relevant to the organization and which measures are truly necessary. Those who can explain which risks cause the most damage and why a specific measure protects against them will gain support and cooperation much faster than those who simply present a compliance framework.
Risk analyses often express risks as low, medium, or high, usually using a risk matrix that weighs probability against impact. This is a quick and practical first step. Research shows why this method of risk analysis falls short: people are consistently poor at estimating probability and impact on such a scale, leading different assessors to score the same risk differently. Consequently, a label like "high" or "medium" often leads to more debate than productive discussion. By translating risks into financial impact—such as revenue loss, liability, and recovery costs—you speak the language that management understands.
The Cyber Risk Assessment from Polar Risk maps out cyber risks and translates them into financial impact. This clarifies which risks carry the most weight and where measures and budget deliver the most value. As such, the Assessment forms a strong starting point for a risk-driven ISMS.
By 2025, 20% of Dutch organizations had already suffered significant damage from a cyberattack (ABN AMRO, 2025). A risk-driven ISMS documents which risks are most relevant and why the corresponding measures are on the agenda. That narrative is far more persuasive to management and the rest of the organization than a list of 93 checked-off measures.
Frequently asked questions about ISMS
What is an ISMS?
An ISMS (Information Security Management System) is a structured framework of policies, processes, and measures that allows an organization to systematically manage, assess, and continuously improve information security. It is not a software package, but a way of working based on the Plan-Do-Check-Act cycle.
Is an ISMS the same as ISO 27001?
No. An ISMS is the system of policies and processes itself. ISO 27001 is the international standard that describes the requirements an ISMS must meet. An organization can also have its ISMS certified against this standard.
Is an ISMS mandatory?
ISO 27001 certification is not legally required in most sectors. However, the Cyber Security Act (CBW/NIS2), which came into effect on August 15, 2026, does require organizations in 18 sectors to analyze cyber risks and take appropriate, proportionate measures. You can find more about the requirements on the page about NIS2/CBW. An ISMS is a common way to organize this risk management in a structured and demonstrable manner.
How long does it take to implement an ISMS?
For an initial working ISMS, you should generally count on a few months, depending on the size of the organization and the scope. Certification often takes longer, as the ISMS must first be implemented and have been running for sufficient time to demonstrate its effectiveness, including through internal audits, monitoring, and management reviews.
What does an ISMS cost?
Costs depend on the scope, the number of employees, and whether certification is the goal. In addition to internal hours, factor in costs for any tooling, external guidance, and the certification audit itself. An ISMS without a certification goal is cheaper, but it does not provide external proof of compliance.
Is an ISMS sufficient to manage cyber risk?
An ISMS manages the process: how risks are identified, assessed, and treated. However, translating cyber risks into euros adds an extra dimension: it makes different cyber risks more comparable to other business risks and supports investment and budget decisions.
Which cyber risks deserve priority attention within your ISMS?






