An ISMS (information security management system) is how an organisation runs information security as a system rather than a set of separate measures: with objectives, assigned responsibilities and a repeating cycle of plan, do, check and act. ISO 27001 is the international standard that sets the requirements for an ISMS, and the standard it is certified against.
An ISMS has a few fixed parts: a defined scope, an information security policy, a risk assessment and a plan for treating those risks, a Statement of Applicability listing the chosen controls, and evidence that those controls work. Internal audits and a management review close the cycle, so the system keeps pace as the organisation changes.
An ISMS is not software but the set of agreements and processes. ISMS software, such as Tidal Control, keeps the system current by holding policies, risks, controls and evidence in one place. A well-run ISMS protects the confidentiality, integrity and availability of information, and shows customers and auditors that security is demonstrably in order.