ISO 27001 Clause 4.4: Information Security Management System (2022)
Read the requirements of ISO 27001 Clause 4.4: Information Security Management System, which requires organisations to establish, implement, maintain, and continually improve an information security management system.
This version of clause 4.4 is applicable to both ISO 27001:2022 and ISO 27001:2013.
“The organisation shall establish, implement, maintain and continually improve an information security management system, including the processes needed and their interactions, in accordance with the requirements of this document.”
In the previous clauses, we defined what is needed for an information security management system, and the final step in setting up an ISMS plainly mandates the organisation to establish, implement, maintain and continually improve its ISMS. It's critical to understand that the ISMS is an ongoing programme which needs constant proactive management and updating.
You should be able to evidence how you have established, through the previous clauses, your ISMS, and how you have implemented it. In terms of maintenance and continual improvement, you should ensure that new, relevant staff are fully aware of the ISMS, as well as consider the impact on the ISMS of any new products and services, processes, suppliers, geographical changes, hierarchical restructures, etc.
Essentially, you need to evidence that your information security management system is a living, evolving entity that receives ongoing maintenance, updating, and improvement.