Plan — Establish the ISMS scope, the risk assessment methodology, and the risk treatment plan. The output is a Statement of Applicability (see next section) and a leadership-signed risk appetite. This is the part where the management system is actually defined, on paper, before any control is deployed.
Do — Implement the selected controls and the training and awareness program that keeps them in use. Day-to-day operations run here: access provisioning runs off the A.5/A.8 identity policy, the change ticket closes against the A.8 secure-development guidance, the backup schedule follows the A.8 backup control.
Check — Monitor, measure, and review the ISMS. Internal audits, control-effectiveness reviews, and the management review meeting all live in this phase. This is where the auditor will look first at certification audit: a missing internal-audit log is the most common major nonconformity.
Act — Address nonconformities and drive continual improvement. Corrective actions, treatment-of-risks updates, and the lessons-learned from incidents all get folded back into the Plan phase. ISO 27001 is explicit about this: an ISMS that does not improve over the audit cycle loses certification at surveillance.