While Information security describes the activities that relate to the protection of information and information infrastructure assets against the risks of loss, misuse, disclosure or damage, the information security management (ISM) describes the controls that an organisation needs to implement to ensure that it is sensibly managing these risks.

