What it means
ISO/IEC 27001 specifies the requirements for establishing, operating and improving an information security management system, with a control set in Annex A. Certification is granted by an accredited body after audit.
The standard asks for a management system, not a control checklist — risk assessment, defined scope, management review and continual improvement. Organisations that treat Annex A as the whole task usually find the audit disagrees.
Where MyRISK fits
What we do about it
MyRISK is not a certification body and does not certify, audit or guarantee an outcome against ISO 27001. Where it helps is the evidence discipline underneath: controls and evidence held once and reused, and decisions recorded in a form a reviewer can follow.
Is this the thing you are actually trying to fix?
A definition rarely settles it. Tell us what happened — the request, the finding, the challenge or the incident — and we will say where to start, or that it isn't us.