Do you need an Information Security Management System (ISMS)?
We will support you in this.
For years, incident and situation reports from the BKA, BSI, World Economic Forum, insurance companies and cybersecurity providers have made it clear that cyberattacks are on the rise – and are perceived as a serious threat. However, many organizations have difficulties addressing the issue of information security and taking concrete measures.
Our solutions.
IT Security Consulting.
SAVe ISMS GRC Software.
We have been working in information security since the 1970s and our experts have also helped shape parts of the BSI IT baseline protection standards. Our team of consultants, data protection officers, pentesters and auditors will support you in all aspects of an ISMS. Thanks to our many years of experience in the public sector and collaboration with numerous private companies, we always approach the development of your ISMS tool in a practice-oriented manner and with the necessary professional respect for your sensitive information.
What is an ISMS?
An information security management system (ISMS) defines procedures and rules by which information security can be permanently controlled, monitored and continuously optimized. The aim is to ensure confidentiality, integrity and availability in line with the CIA principle within your organization; once this has been implemented, an audit can also be carried out. Organizations have the choice between the internationally predominant ISO 27001 (“native”) and the German ISO 27001 based on BSI IT baseline protection (IT-Grundschutz). Regardless of the standard chosen, such an ISMS is the subject of ISO 27001 certification. In addition, there may be other standards such as the Payment Card Industry Data Security Standard (PCI-DSS) or laws such as the General Data Protection Regulation (GDPR, Section 32 (1)), which also place requirements on your information security activities.
Data protection and IT security cannot and should not be left to chance. With an ISMS, organizations manage their information security requirements, set information security goals, develop security guidelines for information security, issue work instructions, put these into practice and monitor whether they are achieving their goals. In this way, you achieve the active implementation of appropriate measures and remain within the framework of the regulatory requirements.
In an information security management system, individual measures are developed and implemented for each company. If there are changes in the company’s business processes, these measures must be modified accordingly, which is why continuous monitoring is necessary.
Advantages of an ISMS.
- Reduced cost of security incidents
- Compliance assured
- Protection of reputation
- Active management of risks
- Transparent security processes
- Transparent risks
- Continuous improvement
The measures you take for your organization depend on your needs, current requirements and risk preferences. You determine your required basic security level. This means establishing an ISMS does not automatically result in higher cyber security for your organization – if, for example, you have set your security level too low and information security is not practiced at all levels on a daily basis. The ISO 2700x standard or IT baseline protection will also not provide you with any clear recommendations for technical solutions or a business return on investment (“ROI”) figure. This must be done through information security concepts or separate calculations.

Depending on the size of the organization, the field of validity of the ISMS and the selected standard, the scope of an ISMS and the associated administrative expenditure can quickly become hard to manage. It is therefore always advisable to use an ISMS GRC tool for the implementation of an ISMS right from the start in order to ensure the greatest possible transparency. Originally developed in the 1990s as software for our consultants, our ISMS GRC tool called SAVe combines our experience in IT security with the risk and compliance management requirements of the future to create a recognized standard that provides all the necessary protection for confidential information.