ISO/IEC 27001¶
ORSM does not replace the Information Security Management System established through ISO/IEC 27001.
ISO/IEC 27001 provides governance, risk management and control-selection structures. ORSM evaluates the operational characteristics of the resulting security architecture.
This includes asking whether implemented controls:
- remain proportionate to current risk;
- introduce unsustainable operational workload;
- create concentrated dependencies;
- can be recovered predictably;
- support continued business operation during failure; and
- continue to justify their lifecycle cost.
ORSM can therefore provide an architectural and operational assurance layer alongside the ISMS.