Sentrix

ISO 27001 guide · Clause 4

4.4 — Information security management system

ISO 27001:2022 sub-clause 4.4 requires establishing, implementing, maintaining and improving an ISMS built around defined processes and their interactions.

By Sentrix · Published 2026-07-16

Two sentences in the standard, and yet the requirement that quietly demands everything else in clauses 5 through 10 actually connect into one system.

In plain language

4.4 requires you to actually build an ISMS — not just satisfy clauses 5 through 10 as disconnected checklist items, but establish, run, maintain, and keep improving a coherent system made up of defined processes that work together.

Why this requirement exists

It is entirely possible to satisfy each clause of the standard in isolation — a risk register here, a training log there, an internal audit somewhere else — without any of them actually talking to each other. This requirement exists to insist on the “system” in “information security management system”: the processes have to interact, not just individually exist.

Scenario: an organization has a risk register, a training program, and an internal audit process, each maintained by a different team with no shared calendar or cross-reference between them. The internal audit never actually checks whether training addressed the risks the register identified, because nobody built the connection between the two processes. Individually, every piece exists; as a system, it does not.

What the standard expects

The standard expects the organization to establish, implement, maintain, and continually improve an information security management system, including the processes needed and their interactions, in accordance with the requirements of this document. The phrase “including the processes needed and their interactions” was made explicit in the 2022 revision, reflecting the harmonized process-based structure shared across ISO management-system standards.

In practice

  • Map how your ISMS processes actually connect: risk assessment feeds treatment, treatment feeds objectives, monitoring feeds management review, management review feeds improvement.
  • Make sure no process owner is working in isolation — internal audit, risk management, and training should reference the same underlying risk and control data.
  • Treat “continually improve” as literal — the ISMS should look different, in small ways, from one year to the next.

Evidence the auditor will ask for

  • A process map or narrative showing how ISMS processes connect and feed each other, not just a list of them.
  • Cross-references between outputs of one clause (e.g. risk treatment) and inputs of another (e.g. security objectives, management review).

Common pitfalls

  • Each clause satisfied in isolation, with no visible connective tissue between them — a common auditor observation even when every individual requirement technically passes.
  • Different teams owning different ISMS processes with no shared calendar, register, or reporting line tying them together.

Related requirements

2013 → 2022 mapping

2022 version2013 versionNature of change
4.4 Information security management system4.4 Same titleReformulated to explicitly require “the processes needed and their interactions”

Sources

Frequently asked questions

Does 4.4 require its own separate documentation?
Not a standalone document — it is typically demonstrated through how the other clauses visibly connect: a process map, cross-references between registers, or simply consistent evidence that one clause’s output feeds another’s input. The auditor is looking for the system in management system, not just a list of processes that happen to exist.
What did the 2022 version change in 4.4?
The phrase “including the processes needed and their interactions” was made explicit in the 2022 revision, reflecting the harmonized process-based structure shared across ISO management-system standards. The underlying requirement is unchanged — establish, implement, maintain, and continually improve the ISMS — but the processes have to interact, not just individually exist.
How do we show that ISMS processes interact?
By mapping how they actually connect: risk assessment feeds treatment, treatment feeds objectives, monitoring feeds management review, management review feeds improvement. No process owner should be working in isolation — internal audit, risk management, and training should reference the same underlying risk and control data, on a shared calendar and register.

Let's talk about your compliance program.

Last updated: 2026-09-17