If you want to implement in your organization a Risk Management Process, Business Continuity Plans, IT Disaster Recovery Plans, Information Security Processes and even Cybersecurity, or any other ISO standard or reference framework, it is most appropriate that know how to design a Management System.
What is a Management System? A management system is a system that allows organizations to establish policies and objectives and subsequently implement them.
According to the ISO/IEC 27000 standard, clause 3.41 this is the definition of a Management System.
- A set of interrelated elements of an organization that interact to establish policies and objectives and the processes to achieve these objectives.
- Note 1 to entry: A management system can address a single office or multiple offices.
- Note 2 to entry: System elements include the structure, roles and responsibilities, planning and operation of the organization.
- Note 3 to entry: The scope of a management system may include the entire organization, specific and identified functions of the organization, or one or more functions within a group of organizations.
What is Annex SL?
It is a unified high-level structure, agreed by ISO/IEC that provides a format and a set of guidelines to follow for the documentary development of a management system.
Goals of Annex SL
- Increase the consistency and alignment of ISO Management Systems through:
- a unified and agreed High Level structure (Annex SL) that will have identical common terms and definitions for all ISO management standards.
- All ISO Management Systems standards requirements will be aligned and the compatibility of your systems increased.
- Each individual standard can add specific requirements for the discipline it handles.
- New management system standards and future revisions of existing standards will increase the value to users.
- Annex SL will be useful for those organizations that operate a single integrated management system that meets the requirements of two or more management standards simultaneously.
- This new structure can be related to the PDCA cycle approach.

Process Approach – PDCA Cycle
The standard promotes the adoption of a process approach to establishing, implementing, operating, monitoring, reviewing and maintaining an organization’s Management System. In this way, the ISO standard adopts the Plan-Do-Check-Act (PDCA) process model for continuous improvement.
A process approach to management encourages its users to emphasize the importance of:
- Understand the requirements of an organization’s standard and the need to establish a policy and objectives for the management system in question;
- Implement and operate controls to manage risks;
- Monitor and review the performance and effectiveness of the Management System and;
- Continuous improvement based on the measurement of the objective.

Por: Ciro Bonilla | Consulting Information Tech & Auditing
