ISMS

ISMS and ISO 9001: Synergies Between Quality and Information Security Management

TL;DR
  • ISO 27001 and ISO 9001 are both based on the High Level Structure (HLS), which means approximately 30 percent of requirements are identical or nearly identical.
  • The greatest synergies lie in context of the organization, leadership, planning, support (documentation, competence), performance evaluation (audit, management review), and improvement.
  • An integrated management system (IMS) is not a third standard but the deliberate merger of shared processes while maintaining discipline-specific content.
  • Companies with an existing QMS can save on average 30 to 40 percent of the effort when building an ISMS, if they leverage existing QMS structures.
  • Integrated audits save time and money: An auditor examines shared requirements only once instead of duplicating them in separate audits.

Two standards, one foundation

If you work in a company that is already ISO 9001 certified and now needs to build an ISMS according to ISO 27001, you have a significant head start. Both standards belong to the ISO family and, since the 2015 revision (ISO 9001) and the 2022 revision (ISO 27001), follow the so-called High Level Structure (HLS), also known as the Harmonized Structure. This is no coincidence — it's a deliberate ISO decision to facilitate the integration of different management systems.

The HLS prescribes a uniform structure of ten chapters with identical core requirements in the areas of context, leadership, planning, support, operation, performance evaluation, and improvement. The discipline-specific requirements — quality management for ISO 9001 and information security controls for ISO 27001 — supplement this foundation.

In practical terms, this means: If you have a functioning QMS, you've already met a significant portion of the ISMS requirements. Not in terms of information security content, but structurally in terms of the management system requirements. And these structural requirements are often what cause the most effort when building an ISMS.

The shared requirements in detail

Chapter 4: Context of the organization

Both standards require that you understand the context of your organization: internal and external issues that influence the management system, and the requirements of interested parties.

Synergies: The context analysis is largely identical. Customers, suppliers, regulators, employees, and society are relevant stakeholders for both systems. You don't need two separate context analyses — just one shared analysis that considers both quality and security aspects.

Differences: The interested parties may differ. For the QMS, customers and their quality requirements are central. For the ISMS, regulators (BSI, data protection authorities), insurers, and potentially threat actors are added as relevant parties.

Practical tip: Extend your existing context analysis to include ISMS-specific aspects rather than creating a new one. Supplement the stakeholder list with information security-specific parties and their requirements.

Chapter 5: Leadership

Both standards require top management commitment: providing resources, defining roles, formulating and communicating policy.

Synergies: Executive management must already commit to quality objectives and policy in the QMS. This commitment can be extended to information security. The management structure (who reports to whom, who has what authority) is already defined and can be used for the ISMS.

Differences: The information security policy is a standalone document alongside the quality policy. The CISO (Information Security Officer) role has no direct counterpart in the QMS (the Quality Management Representative has not been a mandatory role since ISO 9001:2015, but is still appointed in many companies).

Practical tip: If you have both a QMR and a CISO, ensure they work closely together and coordinate their reporting lines to executive management. In smaller companies, one person can fill both roles, provided the competence is there.

Chapter 6: Planning

Both standards require risk-based planning: identifying risks and opportunities and planning actions to address them.

Synergies: The planning process is identical: identify risks, assess them, derive actions, set objectives. If you've already implemented a risk-based approach in your QMS (which ISO 9001 has required since 2015), you can adopt the methodology and process for the ISMS.

Differences: The risk concept differs. In the QMS, risk relates to the ability to meet quality requirements (process risks, product risks). In the ISMS, risk relates to the confidentiality, integrity, and availability of information. Additionally, the risk assessment in the ISMS is significantly more formal: ISO 27001 explicitly requires a risk assessment methodology, a risk acceptance criterion, and risk assessment documentation. ISO 9001 is less specific here.

Practical tip: Use the same risk assessment methodology for both systems, but with separate risk registers. The methodology (scales, assessment criteria, acceptance thresholds) can and should be identical. The risks themselves are different and belong in separate registers.

Chapter 7: Support

Both standards require resources, competence, awareness, communication, and documented information.

Synergies: This is one of the greatest areas of synergy alongside documentation. If your QMS has a functioning document management system (creation, review, approval, distribution, archiving), the ISMS can use exactly the same system. Training and competence management follow the same principles. Communication channels are already defined.

Differences: The ISMS-specific content (security policies, risk reports, incident documentation) must be integrated as document types into the existing system. And the awareness requirements of the ISMS go beyond those of the QMS: all employees must know the security policy, understand what they contribute to information security, and what consequences violations have.

Practical tip: Use the existing document management system for ISMS documents. Extend the training plan to include information security topics. Integrate security content into existing onboarding programs.

Chapter 8: Operation

This is where the standards diverge most, as the operational core is discipline-specific.

QMS (Chapter 8): Planning and control of operational processes, product development, procurement, production, release, control of nonconforming outputs.

ISMS (Chapter 8): Execution of risk assessment and risk treatment, implementation of controls from the Statement of Applicability.

Synergies nonetheless: Supplier evaluation is relevant in both systems. In the QMS, you evaluate suppliers by quality criteria; in the ISMS, by security criteria. Both can be merged into an integrated supplier evaluation process. Similarly, change management can cover both aspects.

Chapter 9: Performance evaluation

Both standards require monitoring, measurement, analysis, internal audit, and management review.

Synergies: This is the second major synergy area alongside documentation. Internal audits can be conducted in an integrated manner: one auditor examines both QMS and ISMS requirements in a single audit. This saves audit days and reduces the burden on the areas being audited. The management review can take place as a joint meeting addressing both quality and security topics.

Differences: The metrics and audit criteria are discipline-specific. A QMS audit examines process conformity, customer satisfaction, and product quality. An ISMS audit examines risk treatment, control effectiveness, and incident management.

Practical tip: Create an integrated annual audit plan that coordinates QMS and ISMS audits. If an area is relevant to both systems (e.g., supplier management), audit it once rather than twice. Conduct the management review as a joint meeting, with one agenda item for quality and one for information security.

Chapter 10: Improvement

Both standards require handling of nonconformities, corrective actions, and continual improvement.

Synergies: The process for nonconformities and corrective actions is identical: identify the deviation, analyze the cause, define a corrective action, implement it, and verify effectiveness. If you have a functioning CAPA process (Corrective and Preventive Action) in your QMS, use it for ISMS deviations as well.

Practical tip: Maintain a shared action register for corrective actions from both systems. This gives you an overall view and helps you recognize connections (e.g., when a quality deviation traces back to a security issue).

The path to an integrated management system

What an IMS is and what it isn't

An integrated management system (IMS) is not a third standard and not an additional certification. It's the deliberate decision to merge shared processes and embed discipline-specific requirements as modules in a common framework.

The result is not less effort for each individual system, but less total effort. Instead of running two parallel documentation systems, two audit processes, and two management reviews, there's one of each with discipline-specific supplements.

Choosing the integration level

There are different levels of integration:

Level 1: Coordinated. Both systems exist separately but are aligned. Shared audit calendar, shared management review, coordinated policies. The integration effort is low, as are the synergies.

Level 2: Partially integrated. Shared processes (document management, audit, management review, corrective actions) are merged. Discipline-specific processes remain separate. This is the most common and pragmatic approach.

Level 3: Fully integrated. A single management system meeting all requirements of both standards. One shared policy, one shared manual, one integrated audit process. This level requires the highest integration effort but offers the greatest long-term synergies.

For most companies, Level 2 is the right starting point. It offers tangible synergies with manageable integration effort and can be gradually developed toward Level 3.

Integration roadmap

If you have an existing QMS and are building an ISMS, I recommend the following roadmap:

Step 1: Inventory of QMS structures. What processes, documents, and tools exist? What works well? What needs to be adapted? Important: This analysis should be conducted together with the QMR, not around them.

Step 2: Identify shared processes. Go through the HLS chapters and identify for each whether the existing QMS process can be used for the ISMS (possibly with extensions) or whether a separate ISMS process is needed.

Step 3: Extend shared processes. Extend document management to include ISMS document types. Extend the audit process to include ISMS criteria. Extend the management review to include ISMS agenda items. Extend the training program to include awareness content.

Step 4: Build ISMS-specific processes. Risk assessment and risk treatment, Statement of Applicability, incident management, controls implementation. These processes are ISMS-specific and have no QMS counterpart.

Step 5: Create an integrated manual. One document describing the entire management system architecture: shared processes, QMS-specific processes, ISMS-specific processes, and their interconnections.

Planning integrated audits

Benefits of integrated audits

An integrated audit examines the requirements of both standards in a single pass. This offers significant benefits:

  • Time savings: Shared requirements (context, leadership, documentation, competence) are examined only once, not twice in separate audits.
  • Less burden: The audited areas need to be available only once, not twice.
  • Better results: The auditor sees the full picture and recognizes connections that remain invisible in separate audits.
  • Cost reduction: Fewer audit days mean lower costs, both for internal audits and certification audits.

Combining certification audits

Most certification bodies offer combined audits for ISO 9001 and ISO 27001. An audit team examines both standards in one audit block, with shared requirements examined only once. The certificates are still issued separately, but the audit effort is reduced by 20 to 30 percent compared to separate audits.

The prerequisite is that the auditors have the qualification for both standards. For certification bodies that have both standards in their portfolio, this is generally not an issue.

Common pitfalls in integration

Pitfall 1: Treating QMS and ISMS as separate worlds

When the QMR and the CISO don't talk to each other, duplication arises. Both create separate context analyses, separate audit plans, and separate management reviews that largely overlap. Ensure from the start that QMR and CISO work closely together and coordinate their activities.

Pitfall 2: Trying to use the QMS one-to-one for the ISMS

A QMS process isn't automatically suitable for the ISMS. The risk assessment in the QMS is often less formal than ISO 27001 requires. The documentation requirements for security policies differ from those for procedures. Critically evaluate each QMS process before adopting it for the ISMS, and adapt it where necessary.

Pitfall 3: Integration at the expense of depth

The temptation to consolidate everything into one document can result in a loss of discipline-specific depth. A risk assessment that tries to cover both quality and security risks simultaneously can become superficial. Keep discipline-specific content separate and integrate only the structural processes.

Pitfall 4: Not involving the QMR

The QMR built and maintained the QMS. If you now build an ISMS that interferes with "their" system, it can be perceived as a threat. Involve the QMR as a partner from the start, not as someone affected. Explain the synergies, show the benefits, and make clear that the IMS benefits both systems.

Effort estimation: Building an ISMS with an existing QMS

How much does an existing QMS actually save when building an ISMS? The answer depends on the maturity and integration level of the QMS:

QMS in place and actively maintained: You save roughly 30 to 40 percent of the total effort. Document management, audit process, management review, corrective actions, and parts of training can be adopted or extended. ISMS Lite supports the integration by allowing shared processes like audit and management review to be mapped once and used for both systems. The risk assessment methodology can be adapted. You focus on the ISMS-specific requirements.

QMS in place but paper-only: The synergies are significantly lower — perhaps 10 to 15 percent. If the QMS isn't being actively followed, the existing processes aren't a reliable foundation. You're effectively building two systems in parallel, with the opportunity to revitalize the QMS at the same time.

QMS currently being established: The best situation for integration from the outset. Planning both systems together from the start saves the most effort long-term. The initial additional effort for planning an IMS rather than two separate systems is more than compensated by long-term efficiency.

The decision of whether and how far to integrate ultimately depends on your organization: its size, culture, available resources, and the maturity of the existing QMS. But one thing is certain: If you consciously leverage the synergies instead of ignoring them, you'll make your life significantly easier.

Further reading

Build an ISMS on a QMS foundation?

ISMS Lite integrates seamlessly into existing management systems. Leverage existing structures and selectively add the ISMS-specific requirements.

Install now