4.4 — Information security management system
Two sentences in the standard, and yet the requirement that quietly demands everything else in clauses 5 through 10 actually connect into one system.
In plain language
In plain language: 4.4 requires you to actually build an ISMS — not just satisfy clauses 5 through 10 as disconnected checklist items, but establish, run, maintain, and keep improving a coherent system made up of defined processes that work together.
Position in the standard
Why this requirement exists
It is entirely possible to satisfy each clause of the standard in isolation — a risk register here, a training log there, an internal audit somewhere else — without any of them actually talking to each other. This requirement exists to insist on the "system" in "information security management system": the processes have to interact, not just individually exist.
Scenario: an organization has a risk register, a training program, and an internal audit process, each maintained by a different team with no shared calendar or cross-reference between them. The internal audit never actually checks whether training addressed the risks the register identified, because nobody built the connection between the two processes. Individually, every piece exists; as a system, it does not.
What the standard expects
The standard expects the organization to establish, implement, maintain, and continually improve an information security management system, including the processes needed and their interactions, in accordance with the requirements of this document. The phrase "including the processes needed and their interactions" was made explicit in the 2022 revision, reflecting the harmonized process-based structure shared across ISO management-system standards.
In practice
- Map how your ISMS processes actually connect: risk assessment feeds treatment, treatment feeds objectives, monitoring feeds management review, management review feeds improvement.
- Make sure no process owner is working in isolation — internal audit, risk management, and training should reference the same underlying risk and control data.
- Treat "continually improve" as literal — the ISMS should look different, in small ways, from one year to the next.
Evidence the auditor will ask for
- A process map or narrative showing how ISMS processes connect and feed each other, not just a list of them.
- Cross-references between outputs of one clause (e.g. risk treatment) and inputs of another (e.g. security objectives, management review).
Common pitfalls
- Each clause satisfied in isolation, with no visible connective tissue between them — a common auditor observation even when every individual requirement technically passes.
- Different teams owning different ISMS processes with no shared calendar, register, or reporting line tying them together.
Related requirements
4.3 ISMS scope
Defines the boundary the system established here operates inside.
10.1 Continual improvement
The ongoing obligation this sub-clause sets in motion.
Parent link: Clause 4 · Context of the organization
2013 → 2022 mapping
Frequently asked questions
Does 4.4 require its own separate documentation?
Turn disconnected compliance checklists into one working system.
Sentrix links your risk register, controls, audits, and reviews together so the ISMS behaves like the connected system clause 4.4 requires.