Home/ ISO 27001 clauses guide/ Clause 4 · Context of the organization/ 4.4 Information security management system
Clause 4 · Context of the organization

4.4 — Information security management system

Two sentences in the standard, and yet the requirement that quietly demands everything else in clauses 5 through 10 actually connect into one system.

Mandatory requirementDocumented information required: No

In plain language

In plain language: 4.4 requires you to actually build an ISMS — not just satisfy clauses 5 through 10 as disconnected checklist items, but establish, run, maintain, and keep improving a coherent system made up of defined processes that work together.

Position in the standard

4.4 · Information security management system ← you are here
See also: 4.1 · 4.2 · 4.3

Why this requirement exists

It is entirely possible to satisfy each clause of the standard in isolation — a risk register here, a training log there, an internal audit somewhere else — without any of them actually talking to each other. This requirement exists to insist on the "system" in "information security management system": the processes have to interact, not just individually exist.

Scenario: an organization has a risk register, a training program, and an internal audit process, each maintained by a different team with no shared calendar or cross-reference between them. The internal audit never actually checks whether training addressed the risks the register identified, because nobody built the connection between the two processes. Individually, every piece exists; as a system, it does not.

What the standard expects

The standard expects the organization to establish, implement, maintain, and continually improve an information security management system, including the processes needed and their interactions, in accordance with the requirements of this document. The phrase "including the processes needed and their interactions" was made explicit in the 2022 revision, reflecting the harmonized process-based structure shared across ISO management-system standards.

In practice

  • Map how your ISMS processes actually connect: risk assessment feeds treatment, treatment feeds objectives, monitoring feeds management review, management review feeds improvement.
  • Make sure no process owner is working in isolation — internal audit, risk management, and training should reference the same underlying risk and control data.
  • Treat "continually improve" as literal — the ISMS should look different, in small ways, from one year to the next.

Evidence the auditor will ask for

  • A process map or narrative showing how ISMS processes connect and feed each other, not just a list of them.
  • Cross-references between outputs of one clause (e.g. risk treatment) and inputs of another (e.g. security objectives, management review).

Common pitfalls

  • Each clause satisfied in isolation, with no visible connective tissue between them — a common auditor observation even when every individual requirement technically passes.
  • Different teams owning different ISMS processes with no shared calendar, register, or reporting line tying them together.

Related requirements

Parent link: Clause 4 · Context of the organization

2013 → 2022 mapping

2022 version 2013 version Nature of change
4.4 Information security management system4.4 Same titleReformulated to explicitly require "the processes needed and their interactions"

Frequently asked questions

Does 4.4 require its own separate documentation?
Not a standalone document — it is typically demonstrated through how the other clauses visibly connect: a process map, cross-references between registers, or simply consistent evidence that one clause’s output feeds another’s input.

Turn disconnected compliance checklists into one working system.

Sentrix links your risk register, controls, audits, and reviews together so the ISMS behaves like the connected system clause 4.4 requires.