An ISMS, an information security management system, is not software or hardware but a set of rules, processes and roles that makes protection manageable: it is clear what you protect, who is responsible, which risks were accepted deliberately and how the result is checked. The international requirements for such a system are set by ISO/IEC 27001:2022.
Key takeaways
At the core of an ISMS is a management cycle: define the scope and the assets, assess the risks, select and implement controls, check how they work and fix what did not. The cycle repeats, so the system does not age together with the threats.
The system has four parts, and technology is only one of them.
An ISMS covers not only technology but also people, contractors and physical access to premises. A leak caused by an employee who said too much is as much an information security incident as a hacked server.
The standard describes what the system must contain but does not dictate the tools. The current edition is ISO/IEC 27001:2022, published on 25 October 2022; in February 2024 it was supplemented by Amendment 1, which added climate action clauses.
The mandatory part of the standard is clauses four to ten: context of the organization, leadership, planning, support, operation, performance evaluation and improvement. Annex A is a catalogue you select from after the risk assessment, not a list that has to be implemented in full.
Important A certificate against the 2013 edition is no longer valid: certification bodies had to move all their clients to the 2022 edition by 31 October 2025. If a counterparty sends you an old certificate, ask for a current one.
Implementation follows the order set by the standard itself: first the boundaries and the rules, then the risks, then the controls. Skipping the risk assessment and starting with buying security tools is the most common and most expensive mistake.
| Stage | What is done | Document produced |
|---|---|---|
| Context and scope | Define the processes, sites and systems inside the ISMS and the requirements of clients and regulators | Scope statement |
| Policy and roles | Management approves the principles and appoints owners of the system, the assets and the risks | Information security policy, order on roles |
| Inventory | Collect the list of data, systems, devices and contractors and assign owners | Asset register |
| Risk assessment | Identify threats, likelihood and consequences, set priorities | Risk assessment method and results |
| Risk treatment | Select controls from Annex A and decide what to do with every significant risk | Risk treatment plan, Statement of Applicability |
| Implementation and training | Configure the controls, write working procedures, train the staff | Procedures, training records |
| Verification | Measure how the controls work, run the internal audit and the management review | Audit reports, management review minutes |
The Statement of Applicability (SoA) is the key document of the whole system. It lists the necessary controls with the justification for including them, a note on whether they are implemented yet, and the justification for excluding any Annex A control. It is what lets an auditor tell a deliberate choice from something simply forgotten.
Risk assessment decides where the money goes, which is why it is the core of the system. ISO/IEC 27005:2022 explains how to manage information security risks and names four decisions for every significant risk.
How to weigh likelihood and impact, which threats are the most common and how to keep a risk register from becoming a formality is covered in our separate article on information security risks.
The standard asks not for a thick folder but for a specific set of records that show the system works. The minimum across clauses four to ten looks like this.
The main quality criterion for a document is whether it can be followed. A procedure nobody complies with is worse than none: it creates an illusion of protection and falls apart at the first audit.
The standard itself is voluntary in Uzbekistan, but part of its requirements is duplicated by law. Article 27 of the Law on Personal Data No. ZRU-547 obliges the owner and the operator to take legal, organisational and technical protection measures, and Article 20, as amended by ZRU-1125, requires the State Register to hold only databases containing data that must be stored inside Uzbekistan (biometric data, genetic data and telecom-subscriber data).
Some industries go further. Commercial banks are covered by the Regulation on minimum information security and cybersecurity requirements, registered under number 3669 on 18 August 2025 and in force since 20 November 2025. For owners of critical information infrastructure the requirements come from the law on cybersecurity and the regulation on protecting such facilities — we covered them in the article on security monitoring and incident response.
The practical conclusion: if you handle customers' personal data, part of an ISMS is needed regardless of any certification plans — at minimum a responsible person, an access procedure, an incident response procedure and records showing that all of it is followed.
A certificate confirms not that you are protected but that the system is built to the standard and running. It is worth ordering when clients, tenders or a regulator ask for it: the paper on its own does not reduce risk.
Certification is carried out by an independent body accredited under the rules of the International Accreditation Forum (IAF); ISO itself does not issue certificates. The check runs in two stages: first the auditor reviews the documents and the scope, then looks at how the system works in practice, from access logs to training records.
After the certificate is issued the body runs surveillance audits and, at the end of the cycle, recertification. So getting a certificate and forgetting about it does not work: internal audits, management reviews and risk reviews continue.
Tip Before budgeting for certification, ask the client or the bank what exactly they need. Often a security audit report and a description of the processes is enough, not a certificate.
A company of 20 to 50 people does not need the system of a large bank. A workable minimum is eight to ten documents that can be followed without a dedicated security department.
The mistakes are almost always the same: downloaded policies written for another business; a scope covering the whole company from day one; a risk assessment done once and never repeated; training reduced to sending out a file; a system with no owner, run by the system administrator in spare time. How to make training work is covered in our article on security awareness training for employees.
Start not with documents but with inventory and risk assessment: before them any implementation plan is guesswork and any deadline is a promise with nothing behind it.
Syntra Systems does not offer ISMS implementation or ISO/IEC 27001 certification support as a separate service. We do the work this starts with — an information security audit from $1,200: we map what needs protecting, check servers, networks, mail, websites and workstations for known vulnerabilities, review access rights and the handling of personal data, and deliver a report where every risk has a likelihood, a consequence and a place in the queue. That is ready material for an asset register and a risk assessment.
The next step is data and access protection from $4,000: roles and two-factor authentication, encryption, protection of mail against spoofing, backups with verified restore, firewall and VPN, incident procedures and staff training. In effect this implements part of the Annex A controls and the working procedures around them. The full scope is on our cybersecurity for business page, and how to build the same requirements into a new system in advance is covered in the article on designing information protection.
Let’s discuss your project
Tell us what you need, and we will estimate the timeline and cost and suggest a solution.
Antivirus and a firewall each close one hole. An ISMS is the order built around them: what the company protects, which risks it covers, who owns that, and how often the protection is checked. Without it, you don't know whether what you bought is enough — or whether you paid for more than you need.
No, certification is voluntary. It is ordered when clients, tenders or a regulator require it. The value comes from the system itself: risk-based priorities, rules people can follow and regular verification. The certificate proves this to an outsider but does not reduce risk on its own.
No. A contractor takes on the work and part of the consequences, but not the liability: under the law on personal data the owner or the operator answers for it. That is why the contract fixes the scope of work, the access granted, the rules for handling data and the incident notification procedure.
The standard doesn't ask for a thick folder but for records that show the system actually works: a policy and its scope, objectives, a risk assessment and treatment plan, a list of the controls chosen, results of internal audits and management review, and a log of nonconformities. What matters most is that it's workable — a procedure nobody follows does more harm than having none.
The ISO/IEC 27001 standard is voluntary in Uzbekistan, but the Law on Personal Data requires the owner and operator to take legal, organisational and technical protection measures — which is part of the same work. Commercial banks and owners of critical information infrastructure face separate mandatory requirements.
Often it is: before budgeting for certification, ask exactly what they need. An information security audit report and a description of your processes is frequently enough; our IS audit starts from $1,200.
Sources