ISMS
An ISMS — information security management system — is the governance loop that runs your security program: assess risks, choose controls, operate them, audit yourself, review at management level, improve. It’s the thing ISO 27001 actually certifies. The controls are downstream; the system that selects and reviews them is the point.
What an ISMS consists of
A defined scope; an approved information security policy; a risk assessment methodology and a living risk register; the Statement of Applicability mapping all 93 Annex A controls to applicable-or-excluded; internal audits; management reviews with recorded decisions; and corrective-action tracking. Each element produces dated records — certification bodies audit the records, not the intentions.
Why it feels heavier than SOC 2
SOC 2 asks “did your controls operate?” ISO 27001 additionally asks “does the machine that chooses your controls actually turn?” That’s more paperwork, deliberately: the ISMS is what keeps a program current after the consultants leave. Teams that build the loop honestly find year two cheaper than year one; teams that fake the loop get caught at the surveillance audit.
Risk Register — A risk register is the living record of identified risks, their scores, owners, and treatments — sampled in every SOC 2 and ISO 27001 audit.
Statement of Applicability — The SoA lists every ISO 27001 Annex A control with your inclusion or exclusion decision and justification — the document certification auditors read first.