The document discusses the ISO/IEC 27001 standard for information security management systems (ISMS). It states that an ISMS under ISO/IEC 27001 establishes, implements, operates, monitors, reviews, maintains and improves information security as part of an organization's overall risk management system. It also requires adopting a process to establish, implement, operate, monitor, review, maintain and improve the ISMS.