LOGBOOK

HELP

1 / 64
Other keys: showSpace: good1-4: rate0: skip5: flag

Question

What is a management system in the ISO 27000 sense?

Answer

A management system is a framework of resources (organisational structures, policies, planning activities, responsibilities, methods, processes) that an organisation uses systematically to reach its objectives.

The formal definition from DIN EN ISO/IEC 27000:2017, Kap. 3.2.5:

"A management system uses a framework of resources to achieve the organisation's objectives. The management system encompasses organisational structures, policies, planning activities, responsibilities, methods, procedures, processes and resources."

In plain terms a management system is the machinery for steering business processes, not the processes themselves. It:

  • Steers day-to-day operations (Prozesse steuern).
  • Structures processes so they're repeatable (Prozessstrukturierung).
  • Optimises existing workflows over time.

Examples:

Management system Steers…
QMS (ISO 9001) Quality of products/services
EMS (ISO 14001) Environmental impact
ITSMS (ISO 20000) IT service delivery
ISMS (ISO 27001) Information security
RMS (ISO 31000) Risk

Tip: A management system is NOT the same as the things it manages. An ISMS is not a firewall — it's the framework that decides which firewalls you need, who maintains them, and how you measure that they work.

Go deeper:

or press any other key

Question

What is the PDCA cycle, and why is it the heart of every modern management system?

Answer

PDCA = Plan → Do → Check → Act. It is the continuous feedback loop that every modern management system uses to drive continuous improvement (kontinuierlicher Verbesserungsprozess, KVP).

Four-phase loop: Plan to Do to Check to Act, with Act feeding back into Plan for continuous improvement

* PDCA as a closed feedback loop — Act feeds lessons back into Plan (KVP / continuous improvement). *

Phase What happens
Plan Define objectives, identify risks, plan controls and processes
Do Implement and operate the plan
Check Monitor, measure, audit — compare to the plan
Act Fix what didn't work, raise the bar, feed lessons back into Plan

PDCA is the engine behind ISO 9001, ISO 14001, ISO 27001, BSI 200-1 and essentially every "Managementsystem nach ISO". Visualised as a spiral, each turn lifts the organisation to a higher level of maturity ("Quality Improvement over Time").

Where it came from:

  • Originally Walter Shewhart in the 1930s as a statistical quality control loop.
  • Popularised by W. Edwards Deming in post-war Japan, which is why it's sometimes called the Deming cycle.

Why this matters for security: "Sicherheit" is not a state you reach once — threats change, the organisation changes, and controls decay. Without an explicit feedback loop, a security programme drifts back into chaos within a couple of years.

Tip: ISO 27001:2022 dropped the explicit PDCA labels from the standard, but the structure (Plan ≈ clauses 4–6, Do ≈ 7–8, Check ≈ 9, Act ≈ 10) is still PDCA in disguise.

Go deeper:

  • doc PDCA (Plan-Do-Check-Act) — origin (Shewhart), Deming's Japan work, and the continuous-improvement loop behind every ISO management system.
The plan–do–check–act cycle
The plan–do–check–act cycle
Karn-b - Karn Bulsuk (http://www.bulsuk.com). Originally published at http://www.bulsuk.com/2009/02/taking-first-step-wi... · CC BY 4.0 · Wikimedia Commons
or press any other key