Do you need an Information Security Management System (ISMS)?

We will support you in this.

For years, incident and situation reports from the BKA, BSI, World Economic Forum, insurance companies and cybersecurity providers have made it clear that cyberattacks are on the rise – and are perceived as a serious threat. However, many organizations have difficulties addressing the issue of information security and taking concrete measures.

Our solutions.

IT Security Consulting.

Read more

SAVe ISMS GRC Software.

to SAVe

We have been working in information security since the 1970s and our experts have also helped shape parts of the BSI IT baseline protection standards. Our team of consultants, data protection officers, pentesters and auditors will support you in all aspects of an ISMS. Thanks to our many years of experience in the public sector and collaboration with numerous private companies, we always approach the development of your ISMS tool in a practice-oriented manner and with the necessary professional respect for your sensitive information.

What is an ISMS?

An information security management system (ISMS) defines procedures and rules by which information security can be permanently controlled, monitored and continuously optimized. The aim is to ensure confidentiality, integrity and availability in line with the CIA principle within your organization; once this has been implemented, an audit can also be carried out. Organizations have the choice between the internationally predominant ISO 27001 (“native”) and the German ISO 27001 based on BSI IT baseline protection (IT-Grundschutz). Regardless of the standard chosen, such an ISMS is the subject of ISO 27001 certification. In addition, there may be other standards such as the Payment Card Industry Data Security Standard (PCI-DSS) or laws such as the General Data Protection Regulation (GDPR, Section 32 (1)), which also place requirements on your information security activities.

Data protection and IT security cannot and should not be left to chance. With an ISMS, organizations manage their information security requirements, set information security goals, develop security guidelines for information security, issue work instructions, put these into practice and monitor whether they are achieving their goals. In this way, you achieve the active implementation of appropriate measures and remain within the framework of the regulatory requirements.

In an information security management system, individual measures are developed and implemented for each company. If there are changes in the company’s business processes, these measures must be modified accordingly, which is why continuous monitoring is necessary.

Advantages of an ISMS.

  • Reduced cost of security incidents
  • Compliance assured
  • Protection of reputation
  • Active management of risks
  • Transparent security processes
  • Transparent risks
  • Continuous improvement

The measures you take for your organization depend on your needs, current requirements and risk preferences. You determine your required basic security level. This means establishing an ISMS does not automatically result in higher cyber security for your organization – if, for example, you have set your security level too low and information security is not practiced at all levels on a daily basis. The ISO 2700x standard or IT baseline protection will also not provide you with any clear recommendations for technical solutions or a business return on investment (“ROI”) figure. This must be done through information security concepts or separate calculations.