The positioning error of QM – and the lessons you can draw from it for your ISMS

Portrait Burkhard Wolkewitz

From

Burkhard Wolkewitz

Posted on

10.9.2026

Setting up an ISMS is one thing. Actually using it in your day-to-day operations is quite another. Ask yourself this: Is your ISMS a document archive, an IT control function, or a driver for business security? Your answer will largely determine whether information security truly becomes part of your daily routine or just something that happens in the background.

Quality management has been asking itself this very question for decades. Anyone building an ISMS today has a rare opportunity: to learn from a history that has already been written.

Clarifying terms: Quality assurance versus quality management

Quality assurance and quality management are two distinct disciplines that nonetheless belong together. Quality assurance is operational and metrics-driven. It monitors products and processes during service delivery, documents deviations, and evaluates error rates. It is indispensable—but reactive, as it identifies what has already happened.

Quality management, on the other hand, places those findings into a broader context to guide the entire company toward a shared understanding of performance. QM uses processes to create clarity: how services are delivered, who is responsible for them, and how quality is systematically improved. It does not act reactively; it acts proactively to shape the organization.

What do QM and ISMS have in common?

Anyone who understands this distinction will immediately notice the parallels to information security management. IT security relates to an ISMS in the same way that quality assurance relates to quality management.

IT security operates on a tactical level: configuring firewalls, installing patches, analyzing logs, conducting penetration tests, and managing access rights. It measures and protects specific technical assets such as systems, networks, and devices. IT security is indispensable.

But it does not answer business-critical questions such as: Which information is vital to our business? Who is responsible for it? How long can we remain operational in the event of a failure?

This is where the ISMS comes in, placing these questions within a governance framework. Risks are assessed, responsibilities are defined, processes are examined, and management is involved. An ISMS shapes the organization rather than just reacting to events.

Admittedly, the analogy is not methodologically perfect. But it is precise enough to pose the crucial question: Are we making the same positioning mistake in information security management that quality management made thirty years ago?

History repeats itself

When ISO 9001 introduced the concept of management systems in the 80s and 90s, the following happened in many companies: the new responsibility was assigned to someone already on staff. The quality assurance manager became the quality management representative. The title changed, but the perception of the role within the company did not.

The problem: The QMRs wrote process descriptions that the departments couldn't relate to. Management signed the quality policy and considered the task complete. The management system was running—but it wasn't driving anything.

A global ISO study of over 8,000 participants shows that the greatest difficulties with ISO 9001 to this day do not arise from technical standard requirements, but from leadership, the organizational context, and integration into the various departments. (Source: ISO/TC 176 User Survey, 2022)

Today, this pattern is repeating itself with ISMS. Information security ends up in the IT department, which is suddenly tasked with the role of Information Security Officer. As with the quality management representatives of the past, only the title changes, not the perception within the company. Experience from QM teaches us the consequence of this: the ISMS is running, but it is not effective.

Limits of this analogy and what they mean for ISMS

Regardless of these parallels, there is one important difference that raises the bar for an ISMS even higher than for QM. In quality management, deviations usually occur unintentionally due to errors, process weaknesses, or material failure. The management system must identify root causes and improve workflows. The adversary is variance.

In information security management, however, we are often dealing with an intentional and intelligent adversary. An attacker adapts their approach. They learn, react, and specifically search for security vulnerabilities. This makes IT security fundamentally more dynamic than quality control. The threat landscape is actively changing because people are changing it.

An ISMS that only documents and assesses risks once a year not only loses its effectiveness, but also poses risks by creating a false sense of security.

For the development of an ISMS, this leads to a clear conclusion: the process orientation that makes QM an effective management system is also the right approach for ISMS. Additionally, ISMS requires a culture of vigilance, both in the departments and at the leadership level, as well as in everyday operations. Not out of fear, but out of an informed awareness of risk.

Insights from 30 years of quality management

The history of quality management teaches us three lessons that are of great value for the successful development of an ISMS.

First: Effectiveness is created by people, not by systems.

Lesson from QM: A management system is only effective if the people working with it find it useful. Not as a tool for control or a driver of bureaucracy, but as a tool that provides guidance and structure while making their own work easier.

Meaning for your ISMS: Policies, risk analyses, and protective measures must be formulated in the language of the departments. Sales must understand why customer data is worth protecting. Production must have internalized what an ERP failure means for the company. This understanding does not come from annual training sessions: it comes from a management system that is present in everyday life.

Second: Responsibility belongs where the work is done.

Lesson from QM: Quality management representatives who are solely responsible for the quality of the entire company fail. Not because they are incompetent, but because quality is created where processes are executed—in the departments.

Meaning for your ISMS: The head of sales knows the critical customer information. The head of development is aware of which technical specifications must not be leaked. And the production manager knows the consequences of a system failure for delivery capability. This expert knowledge belongs in the risk analysis—not an external assessment by IT.

Third: The best way to get started is through processes

A lesson from QM: Management systems that cling to abstract standard structures fail to gain traction in day-to-day operations. A system becomes effective when it connects to something the organization is already familiar with: its own processes.

What this means for your ISMS: Information is not processed in isolation, but embedded within a business process. A sales process handles different information than development, and development handles different information than procurement. This is precisely why starting with processes is the most direct way to derive protection requirements, risks, and measures in a way that is understandable for everyone involved.

The decisive advantage: ISO 9001 as a starting point

The mistakes of the past offer an opportunity that quality management didn't have: if you are building an ISMS today and already operate under ISO 9001, you don't have to start from scratch.

In that case, processes are already documented, responsibilities are defined, the PDCA principle is known, and risk awareness is already established. In practice, ISO 9001 often serves as the foundation for other management systems. This is also evident in the fact that almost all users of energy or environmental management systems use this standard as a common base. (Source: BAM/DIN: The use and impact of standardized management systems, focus study, 2021)

An ISMS builds on this very foundation and views the same business processes from an additional perspective. What information is processed here? What protection goals apply to confidentiality, integrity, and availability? What happens if this process fails?

This means: QM and ISMS are not mutually exclusive. They reinforce each other when integrated. Not as two separate standards side-by-side, but as two perspectives on the same process landscape.

An integrated management system that combines both views does not double the workload. Instead, it complements what is already there, achieving an impact that an isolated ISMS cannot reach.

The most important insight for your ISMS implementation

Companies currently building their ISMS structures are aware of the flawed history of quality management and can prevent it from repeating itself.

It took QM a long time to evolve from a document manager into a true driver of quality. This path, which was actually avoidable, often resulted from (unconscious) positioning decisions. The perception of QM determines its impact.

Today, you can take a shortcut when introducing your ISMS. Make it clear from the start that information security is not an IT project and that risks must be assessed where they arise. After all, a management system only works if it is used in everyday operations.

An ISMS that is understood and implemented in this way makes a significant contribution to the stability, agility, and reliability of your company. And not just today, but also in the future as the threat landscape continues to evolve. When set up correctly, information security management does not lead to more bureaucracy, compliance effort, or IT control, but to genuine empowerment.

No items found.

Your question to Carsten

Sign in to get in touch with Carsten directly.

Don't miss any more new posts!

Always stay up to date: In our newsletter, we provide you with a fresh update on the Modell Aachen Insights every month.

Desktop and mobile illustration

Similar posts

See all posts