An ISMS is a defined, documented way of running security as a system: a scope statement saying what the system covers, a risk assessment and treatment plan, the policies and controls that treatment selects, and — the part teams underestimate — the management loop that keeps it all alive. That loop is internal audits, management reviews, corrective actions, and continual improvement. The ISO 27001 clauses describe the system itself; the controls it governs are chosen through risk treatment and recorded in the Statement of Applicability.
This is the most common misunderstanding about ISO 27001: buying security tools doesn’t produce an ISMS, and an auditor can’t certify a stack of products. Certification attests that a management system exists, that leadership directs it, and that it corrects itself when something drifts. That’s why two companies with identical Annex A controls can have very different audits — one has a system producing those controls, the other has artifacts with nothing behind them.
The certification sprint builds the ISMS; the harder problem is operating it. Risk reviews recur, internal audits recur, surveillance audits arrive annually, and every recurring task needs an owner. That ownership question — who actually runs the system once the initial push ends — is worth answering before you scope the certificate, not after.