What it means
An ISMS is the set of policies, processes, roles and controls through which an organisation manages information security, together with the management review and improvement cycle around them. ISO 27001 is the standard that specifies one.
An ISMS is judged on whether it operates, not on whether it is documented. The evidence of operation — reviews actually held, actions actually closed, risks actually reassessed — is what an auditor asks for and what is usually assembled late.
Where MyRISK fits
What we do about it
Holding that evidence as it is produced rather than reconstructing it is what Core is for, and keeping the review rhythm running is what Essentials is for.
Is this the thing you are actually trying to fix?
A definition rarely settles it. Tell us what happened — the request, the finding, the challenge or the incident — and we will say where to start, or that it isn't us.