ISMS
Information Security Management System — the documented policies, processes, and controls an organization establishes to manage information security risk under ISO/IEC 27001.
In practice
An ISMS in practice is a living set of documents and processes an engineering organization actually runs: a risk register reviewed on a schedule, a Statement of Applicability tied to that risk assessment, management review meetings with minutes, and named control owners who can produce evidence on demand. ISO/IEC 27001 certifies that this system exists and operates continuously — not that any single technical control is flawless.
Common confusion
People sometimes treat "ISMS" as a synonym for a security policy binder or a compliance-automation dashboard. It's neither — it's the management system itself: the cycle of risk assessment, control selection, implementation, monitoring, and continual improvement defined in ISO/IEC 27001 clauses 4 through 10. A folder of policies without an operating review cadence behind it is not an ISMS.