An ISMS is a systematic framework of policies, processes, people and technical controls for managing information security risk. ISO 27001 specifies the requirements for one.
It is a system, not a control set
The most common misunderstanding is that ISO 27001 is a list of security controls to implement. Annex A does contain controls, but the certifiable requirements are clauses 4 to 10 — context, leadership, planning, support, operation, performance evaluation and improvement.
An organisation with excellent technical security and no management system will not pass. One with modest controls, chosen deliberately on the basis of assessed risk and reviewed regularly, will.
Risk-driven by design
The controls you implement follow from your risk assessment, and the reasoning is recorded in the Statement of Applicability. This is why two certified organisations of similar size can have quite different control sets and both be entirely compliant.
Scope
ISMS scope can be narrower than the organisation — a single product, a single site, a single business unit. Customers asking for your certificate will read the scope carefully, so a scope that excludes the service they are buying is of limited use to them.
Under ISO/IEC 27006-1:2024, audit time is calculated on the number of people working within the ISMS scope, and the previous requirement to automatically factor in physical locations was removed.
Cost, honestly
ISO 27001 audit time runs meaningfully higher than ISO 9001 at the same headcount — commonly cited figures put a ten-person organisation at around five audit days where ISO 9001 gives two. Any single blended cost range covering both standards is understating one of them.