Skip to content
Secantra

Product

What an information security management system actually looks like.

An ISMS is the set of decisions an organisation makes about protecting information — what is in scope, which requirements apply, who owns them, and what proves any of it is true. Secantra keeps those decisions as records, not documents.

Definition

A management system, not a set of documents

ISO/IEC 27001 defines an information security management system as part of the overall management system — the policies, processes and resources an organisation uses to establish, implement, maintain and continually improve information security. Two words in that sentence do the work. System: the parts are connected, so a change in one place shows up in the others.Management: somebody decides, somebody owns it, and the decisions can be reviewed.

Most descriptions stop at the artefacts — a policy set, a risk register, a Statement of Applicability, an audit trail. Those are outputs. The ISMS is what produces them and keeps them true between audits, which is the hard part and the part that decays first.

The practical test is not whether the documents exist. It is whether you can answer three questions on an ordinary working day, without starting a project: what is in scope right now, who owns each requirement, and what proves the control behind it is working.

  • Not a policy folder

    A folder is a snapshot of decisions somebody made once. A management system keeps the decision, its reason, its owner and its review date — and tells you when one of them has gone stale.

  • Not an audit project

    Certification is an outcome of the system, not the system. A programme that wakes up eight weeks before the auditor is a project with an ISMS-shaped deliverable.

  • Not a checklist of someone else's requirements

    Clauses 4 to 6 require you to determine your own scope, interested parties and objectives. A tool that carries Annex A alone can prepare an audit; it cannot run the system.

Why it exists

Five problems every ISMS runs into

  • 01

    More regulation, every year

    NIS2, DORA, ISO 27001, PCI DSS and sector rules stack up. Tracking changes and assembling evidence by hand is the job nobody has time for.

  • 02

    Too few qualified people

    Mid-size and public-sector organisations feel it most. Even with tools in place, there is no capacity to run them properly.

  • 03

    Leadership cannot see the state

    The CISO and the board lack an operational picture of risk, compliance and exposure — and audits become a scramble to prove maturity.

  • 04

    Fragmented tooling

    Dozens of unconnected systems, no single view of security and compliance, the same asset described three different ways.

  • 05

    Spreadsheets and manual work

    Compliance and risk still live in Excel. Inventory, policies, tasks and threats are not linked, so nothing stays current.

Architecture

Requirements at the base. Assets and risks at the core.

The foundation is requirements — the regulator's and your own. From them follows what is in scope and who owns it, which risks it carries and what you accept. The platform's job is to make that loop simpler and more automatic than the spreadsheets it replaces.

  1. How · the foundation

    Requirements

    Regulatory — DORA · NIS2 · ISO/IEC 27001 as versioned packs; applicability decided per requirement. Internal — your own policies, standards and business requirements, on the same footing.

  2. What

    Assets

    What do we protect? What must comply — and who owns it? What does it depend on?

  3. Why

    Risks

    What do we fear to lose? At what cost — and what do we accept? Which assets carry it?

one recordrequirements · assets · risks · evidence

  • Simplify
  • Automate
  • Prove
  • Govern
  • Simplify

    one record instead of five tools

  • Automate

    posture derived, record kept current

  • Prove

    evidence with recency, immutable audit trail

  • Govern

    approvals, acceptance, reviews as workflows

Anatomy

What an ISMS has to contain

Clauses 4 to 10 of ISO/IEC 27001 are the management system; Annex A is the control catalogue you choose from inside clause 6. Status is stated honestly: LIVE is in the product today, PARTLY means the data model supports it but a workflow is not in the current release, PLANNED means not yet.

ISO/IEC 27001 clauses 4–10 and where each one lives in Secantra
ClauseRefWhat it asksIn SecantraStatus
Context of the organisation4Determine the issues, the interested parties and their requirements; define the boundary of the ISMS.An organisation risk profile carrying mission, obligations, methodology and appetite; applicability decided at five scopes — tenant, asset, IT service, business solution or process.LIVE
Leadership5A policy, and roles, responsibilities and authorities assigned by top management.Governance documents from platform templates with immutable revisions and single, sequential or mixed approval schemes; roles, and four-eyes approval per flow, on by default.LIVE
Planning6Risk assessment and treatment, the Statement of Applicability, security objectives.A register with a CIS RAM-inspired 1–5 × 1–5 method snapshotted per assessment, treatment plans and approval-gated acceptance. Every requirement carries an applicability decision with its reason — the decision log a Statement of Applicability summarises.LIVE
Support7Resources, competence, awareness, communication, documented information.Documented information is covered: versioned governance documents, evidence records with recency rules, an immutable audit event behind every write. Awareness training is not in the current release.PARTLY
Operation8Run the processes; carry out risk assessment and treatment at planned intervals.Scheduled activities and windows, task and action tracking, findings with owners and due dates.LIVE
Performance evaluation9Monitoring, measurement, internal audit, management review.Assessments against controls, requirements or whole frameworks; audits with a plan built from the adopted framework, typed evidence and a four-eyes sign-off that freezes the record; posture snapshots explainable line by line. The management review itself is a governance document, not a dedicated workflow.PARTLY
Improvement10Nonconformities, corrective action, continual improvement.Findings raised against requirements, controls or assets, assigned to owners, driven to closure, with the audit trail behind each step.LIVE

Annex A is not the management system. Its 93 controls are a catalogue you select from in clause 6 and justify in the Statement of Applicability — which is why a tool that models Annex A alone can produce a control list and still not run an ISMS.

Foundation

Why the asset register sits underneath

A requirement applies to something. A control protects something. A piece of evidence proves something about something. In every case the something is an asset — a system, a service, a supplier, a process, a place where data lives.

When the asset list lives in a different tool from the compliance list, every one of those links becomes a name typed twice. The two lists agree on the day they are reconciled and drift on every day after it, and the drift is invisible until an auditor picks the one system nobody moved across.

Here they are the same record. Assets roll up into IT services, IT services into business solutions, and structural links are validated rather than assumed — so questions that normally take a week are a traversal: what does this business solution depend on, which of its requirements are unmet, whose evidence expired, and which supplier is behind the control that failed.

That is the whole reason a CMDB belongs in an ISMS rather than beside one. Compliance, risk and governance stop being three inventories with a reconciliation problem and become three views of one asset register.

See how the asset register is built →

Failure modes

Four places an ISMS goes quietly out of date

  • 01

    Posture that was typed, not derived

    A percentage somebody entered is true on the day it is entered. Derived posture is computed from adoption, applicability, coverage and evidence; a snapshot is a frozen copy of that computation, explainable line by line — not a score.

  • 02

    Evidence that expired without saying so

    Evidence has a date. A control proven eighteen months ago is not proven now. Recency rules flag what needs revalidation before an auditor asks, instead of after.

  • 03

    A scope decided once

    Applicability is where an ISMS quietly stops matching the organisation. Each decision carries its reason and its scope, so "not applicable" stays reviewable rather than inherited.

  • 04

    Two inventories that disagree

    A compliance list and an asset list drift apart the moment they are two lists. Here the compliance targets are the assets — the same records, the same owners, the same lifecycle.

Modules

What is live today

  • Compliance management

    Adopt any of twelve versioned frameworks — 833 requirements, ISO 27001 to the EU AI Act — decide applicability, map controls, collect evidence. Posture is derived from that record.

    Compliance management →
  • CMDB

    Assets, IT services and business solutions with ownership, criticality and structural relationships. Import, connectors, topology and data quality.

    CMDB →
  • Risk management

    A register with structured assessment, treatment and acceptance, review reminders and a cost-of-risk view — every risk linked to what it threatens.

    Risk management →

Also in every tenant workspace

  • Governance

    Policies and governance documents from platform templates; immutable revisions; single, sequential or mixed approval schemes

  • Audit & assessment

    Audits with a plan built from the adopted framework, explicit scope with justified exclusions, typed evidence, findings as tasks with subtasks — and a four-eyes sign-off that freezes the record

  • Reports

    Framework status, risk register, asset inventory and an executive summary — immutable snapshots generated from the record, as CSV and PDF

  • Integrations & API

    A connector platform with encrypted credentials, scheduled runs and per-record history — Entra ID directory sync live, more connectors in build; CSV, DOCX and framework-pack imports; a documented REST API for everything

  • Third-party registry

    Suppliers, vendors, MSPs, cloud and ICT providers with DORA / NIS2 classification fields, linked to assets and risks

  • Files

    Evidence and document storage: private bucket per tenant, ClamAV scanning that fails closed, retention and legal-hold guards

  • Notifications

    E-mail delivery with configurable providers, sender identities, a template catalog and a delivery log

  • Administration

    Users, roles, approvals, subscription and workspace settings

Platform

Built to grow on the same record

New capabilities land as modules on the data model you already keep — assets, owners, requirements, evidence — never as another tool with another inventory. New regulation does not mean a new programme either: framework versions are pinned, succession is explicit, and a new standard enters as a pack — that is how ISO 42001 and the EU AI Act landed as imports, not releases, and how the next standard will too.

  • One data model

    Every module reads the same assets, owners, controls and evidence.

  • One workspace

    New modules appear in the same navigation, same roles, same audit trail.

  • One posture

    Nothing is re-entered; nothing is reconciled by hand.

Talk to us about what is next for your sector →

Questions we get asked about running an ISMS

Is an ISMS the same thing as ISO 27001?

No. ISO/IEC 27001 is the standard that specifies requirements for an information security management system; the ISMS is the system your organisation actually runs. You can operate an ISMS without certifying it, and you cannot certify without operating one.

Do you need software to run an ISMS?

No, and a small scope runs on documents for years. Software starts paying when the same asset, owner or control has to be true in several places at once — which is the point at which spreadsheets begin to disagree with each other.

What is the difference between an ISMS and a GRC tool?

Scope. GRC usually spans compliance, risk and audit across an enterprise; an ISMS is specifically the management system for information security, with a defined boundary and a standard behind it. Secantra runs an ISMS on a GRC-shaped data model, which is why the asset register sits underneath it.

Does an ISMS have to cover the whole organisation?

No. Clause 4 asks you to determine the boundary and to be able to justify it. What matters is that the boundary is explicit, reviewable, and that everything inside it is genuinely covered.

Can one ISMS cover ISO 27001, NIS2 and DORA at the same time?

Yes, and in the EU that is the usual case. The requirements differ; the assets, owners, controls and evidence underneath them do not. Each framework is adopted as its own versioned pack and they share the record beneath.

Where do our own requirements live?

In the same place as the standard's. A requirement you write yourself is stored in the same shape as a framework's, with the same applicability decision, the same evidence rules and the same posture arithmetic.

See it on your own frameworks

A walkthrough on a workspace set up for your sector. No trial sign-up, no credit card.