Recommended Free Tools
ISACA’s Business Model for Information Security (BMIS) is a business-oriented model for understanding how information security relates to an enterprise’s organisation, processes, people and technology. It helps security teams and business leaders examine how those areas interact; it is not a security standard, certification or ready-made compliance checklist.
What is the Business Model for Information Security?
BMIS gives security professionals and business management a shared way to discuss information security in relation to enterprise governance and objectives. ISACA’s glossary describes it as a model that helps those groups understand information security in the context of the enterprise system.
Rather than treating a security issue as an isolated technical problem, BMIS prompts people to consider the organisational conditions, business activities and human behaviour connected to it. The model’s central question is how security decisions and changes in one part of the enterprise affect the others.
What are the four BMIS elements?
ISACA’s 2010 guide organises BMIS around four elements:
#1 Best Overall
- Organisation: enterprise design, strategy, governance, roles and the structure in which security operates.
- Process: business and security activities that security enables or affects.
- People: individuals and groups, including their roles, behaviour, skills and interactions.
- Technology: the technical applications and systems used across the enterprise.
These are not independent workstreams. For example, a technology change can alter a business process, require new skills or responsibilities, and expose gaps in governance. BMIS encourages stakeholders to look at those relationships together.
What do BMIS’s six interconnections mean?
The model links its four elements through six dynamic interconnections: Governing, Culture, Architecture, Enabling and Support, Human Factors, and Emergence. ISACA names these connections in its 2019 Journal article on risk transformation as well as in the original guide.
- Governing concerns how direction, oversight and accountability connect security to enterprise objectives.
- Culture highlights the shared norms and assumptions that shape security decisions and behaviour.
- Architecture draws attention to how enterprise design and technical arrangements fit together.
- Enabling and Support focuses on the conditions and resources that help people carry out processes and use technology.
- Human Factors centres the effects of people’s capabilities, actions and interactions on security.
- Emergence signals that outcomes can arise from interactions among the elements, rather than from any one component alone.
The interconnections are useful as prompts for analysis, not as a prescribed sequence of steps. The point is to avoid assuming that a technical fix will address a problem whose causes also involve governance, culture, processes or staff capabilities.
How can organisations use BMIS?
Use BMIS to frame conversations and diagnose relationships before choosing controls or changes. A practical discussion can start with a business objective or a security concern, then ask which elements and interconnections influence it.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
- Define the business outcome or concern. State what the enterprise is trying to achieve or what security issue needs attention.
- Map the four elements involved. Identify relevant organisational arrangements, processes, people and technology.
- Examine the interconnections. Ask how governance, culture, architecture, support and human factors influence the situation, and whether combined effects may produce unexpected outcomes.
- Assess the current state. Identify which capabilities or relationships are working and where they need attention.
- Select implementation guidance separately. Choose applicable standards, frameworks or other methods to specify and implement the controls or practices needed.
ISACA’s 2019 article uses BMIS to help identify levers in a risk-transformation effort and describes assessing the current state before deciding which capabilities need enhancement. That example illustrates an application; BMIS itself does not supply a complete implementation procedure.
How is BMIS different from a security standard or framework?
| Aspect | BMIS | Standards and frameworks |
|---|---|---|
| Purpose | A model for analysing and communicating how enterprise elements relate to information security. | May provide implementation guidance, requirements or controls, depending on the specific standard or framework. |
| Scope | Enterprise relationships among organisation, process, people and technology. | Scope and detail depend on the particular publication or framework. |
| Relationship | Can help provide context for security work. | Can be used alongside BMIS to guide implementation; BMIS is not a substitute for them. |
ISACA’s announcement and guide describe BMIS primarily as a model and say it should be supported by standards and frameworks. It is not a certification or a plug-and-play checklist.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.When did ISACA introduce BMIS?
ISACA introduced BMIS to the security community in January 2009, according to its guide. SecurityWeek’s report titled “ISACA Issues New ‘Business Model for Information Security’” appeared on 7 October 2010, covering the model’s publication as an educational resource. The dates refer to different milestones, not conflicting launch dates.
In its 2010 announcement, ISACA characterized BMIS as a holistic, dynamic, vendor- and technology-neutral approach intended for use across industries and countries, and as complementary to other security frameworks. Those are statements from the announcement, not a guarantee that the model fits every organisation without adaptation.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Why connect security to business objectives?
The original guide says: “The security programme exists not only to protect business information, but also—and primarily—to support the business in reaching its objectives.” That statement captures BMIS’s business-oriented emphasis: security is considered in relation to what the enterprise needs to accomplish, not only as a set of technical protections.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

