Skip to content

Information System

What is Information System?

An integrated set of components for collecting, storing, processing, and communicating information that requires security protection.

Information Security

Each of these is named in at least one of the same controls as information system. The number is how many controls name both.

What the standards actually require on information system

Requirements naming information system across 6 standards, quoted from the control text.

Designate a person responsible for information system security and make that role known to the staff.

ANSSI-HYG-39 · Designate an Information System Security Officer and Make the Role Known
NIST SP 800-1289 controls

Establish secure configuration settings that reflect the most restrictive mode consistent with operational requirements.

SP800-128-SECURE-CONFIG · Secure Configurations of Information Systems
ISO 27002:20225 controls

Requires audit tests and other assurance activities that assess operational systems to be planned and agreed in advance between the tester and the appropriate management.

iso-27002-2022::8.34 · Protection of information systems during audit testing
NIS2 Directive4 controls

The first of the ten minimum measure categories requires both a method for analysing risk and the security policy set that the analysis feeds.

nis2-directive::Art.21.2.a · Policies on risk analysis and on information system security

Develop the Information System Contingency Plan (ISCP) per NIST SP 800-34 Rev 1 Section 3.5 + Appendix A (Sample ISCP Template). ISCP must include (a) Supporting Information per Section 3.5.1: introduction + concept of operations + system description and archi...

NISTSP34-4 · Information System Contingency Plan (ISCP) Development

Sets requirements for the creation and operation of personal data information systems.

AZ-DPA-11 · Article 11 - Characteristics of personal data information systems

Questions people ask about information system

What is Information System?
An integrated set of components for collecting, storing, processing, and communicating information that requires security protection.
Why is Information System important for compliance?
Information System is a key concept in Information Security. Understanding information system helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Information System?
Information System appears in the requirement text of ANSSI Guide d'hygiene informatique (42 mesures, v2.0), NIST SP 800-128, ISO 27002:2022, NIS2 Directive, NIST Special Publication 800-34 Revision 1, Contingency Planning Guide for Federal Information Systems. Across these standards we have identified 40 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Information System?
Explore our compliance framework pages to see how information system applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Information System applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.