Screenata

Beyond SOC 2

What are the three main ISMS pillars?

August 22, 20263 min read

What are the three main ISMS pillars?

The three main pillars of an ISMS are people, processes, and technology. An information security management system is the organized way a company manages security risk, and the pillars describe what it is made of: trained and accountable humans, documented and repeated procedures, and tools that enforce and monitor controls. Security failures trace back to a weak pillar far more often than to a missing product, which is why the model persists. No single pillar can compensate for the other two.

Untangling the question first

People searching "what are the three main ISMS" are usually asking one of three different things, so it is worth separating them:

  • The three pillars of an ISMS: people, processes, technology. This page's subject, and what the phrase almost always means.
  • The CIA triad: confidentiality, integrity, availability. These are the three objectives an ISMS protects, defined in ISO 27000's vocabulary. They are properties of information, not components of a management system.
  • ISO 27001: the certifiable international standard for building and operating an ISMS. It is one standard, not three, and it does not use the word "pillars" anywhere.

The pillars and the CIA triad get merged in search results because both are security triads. The clean distinction: the CIA triad is what you protect, the pillars are what you protect it with.

The three pillars in practice

PillarWhat it coversHow it fails
PeopleHiring screening, security training, defined roles and ownership, offboarding, accountabilityAn employee reuses a breached password, or nobody owns access reviews so departed staff keep credentials
ProcessesPolicies, risk assessments, incident response procedures, change management, periodic reviewsThe incident response plan exists as a document nobody has rehearsed, so the first real incident is improvised
TechnologyAccess control, encryption, logging and monitoring, endpoint protection, backupsTools are bought but half-configured; alerts fire into a channel nobody reads

The failure column is the point of the model. Most organizations over-invest in the technology pillar because it is purchasable, while the people and process pillars require sustained management attention. An ISMS is the mechanism that forces attention onto all three: it assigns owners (people), mandates recurring activities like risk assessments and access reviews (processes), and requires evidence that tools actually operate (technology).

Where ISO 27001 fits

ISO 27001 is the standard you certify an ISMS against, and its structure confirms the pillar model without naming it. The 2022 edition of its control set (Annex A, drawn from ISO 27002) contains 93 controls in four themes: organizational (37 controls), people (8), physical (14), and technological (34). People and technological themes map directly onto two pillars; organizational controls are mostly process; and physical controls are the one area the three-pillar shorthand undersells, which is why some teachings add "physical" as a fourth pillar.

Certification is also where the pillars stop being a metaphor. An ISO 27001 auditor samples all of them: training records and role definitions for people, documented and executed procedures for process, and configuration and log evidence for technology. A company strong in one pillar and absent in another does not pass, because the standard audits the management system as a whole.

Why the model is useful beyond ISO 27001

The pillars apply to any security program, certified or not. SOC 2's Trust Services Criteria test the same three surfaces: personnel controls, documented processes, and technical safeguards. If you are building a program from nothing, the pillars are a reasonable order of operations check: for each risk you care about, ask who owns it, what procedure addresses it, and what tool enforces it. A risk with answers in only one column is the gap an auditor, or an attacker, finds first.

Connect and see

See your SOC 2 with your real systems.

Connect GitHub and cloud read-only. Vera shows your control matrix, policy gaps, and prioritized next actions before you commit to anything.