Section 2(1)(f) in The Information Technology (Information Security Practices and Procedures for Protected System) Rules, 2018
(f)"Information Security Management System" means a set of policies, processes and procedures to establish, implement, operate, monitor, review, maintain and continually improve information security and minimize the risks by developing, maintaining, implementing and reviewing the adequate and appropriate security controls;