Portfolio

Core ISMS Capability Model

Seven interdependent capabilities for building an ISMS that drives security decisions rather than merely satisfying an audit.

By Sten Eikrem

Most organisations treat their ISMS as an ISO 27001 compliance exercise: policies, procedures, and evidence artefacts assembled to satisfy auditors. The certificate goes on the wall. The management review happens annually. The risk register gets updated before surveillance audits.

This misses the point entirely. An ISMS is a management system. Built properly, it drives security decisions, allocates resources to actual risk, and provides the organisation with genuine visibility into its security posture. Built for compliance, it produces documentation that satisfies auditors whilst security decisions continue to be made informally, inconsistently, and without accountability.

I publish this framework because transparency builds trust. This is the methodology I apply in practice, adapted to each organisation’s context, maturity, and risk profile.

The model

Core ISMS capabilities framework

The capability wheel maps seven areas that an ISMS must address to deliver real security value. Each operates across the three lines model and none stands alone.

Seven capabilities

  1. Risk Management: know our exposure. Decision support for the business, not a compliance artefact.
  2. Governance: decide what to do and not do. Accountability structures that make real decisions.
  3. Policy and Guideline, KPIs: what we must do, how we measure. The documented expectations and the evidence they are met.
  4. Instructions: how we do it. Operational procedures that translate requirements into daily practice.
  5. Communication: shared understanding that is acted upon, not messages sent. Strategic, tactical, and operational information flows.
  6. Controls: plan, design, implement, update and retire. The measures that actually reduce risk.
  7. Assurance: validating and giving guidance. Systematic evidence that the system works.

How the capabilities work together

These capabilities overlap and reinforce each other. A control without a policy basis lacks authority. A KPI without governance context measures the wrong thing. Risk management without communication produces assessments nobody acts on. Instructions without controls lack rationale. Governance without risk input makes decisions in the dark.