Read the requirements of ISO 27001 Clause 4.4: Information Security Management System, which requires organisations to establish, implement, maintain and continually improve an information security management system.
This version of clause 4.4 is applicable to both ISO 27001:2022 and ISO 27001:2013.
“The organisation shall establish, implement, maintain and continually improve an information security management system, including the processes needed and their interactions, in accordance with the requirements of this document.”
In the sections above we defined what is needed for an ISMS and the final step in setting up an ISMS plainly mandates the organisation to establish, implement, maintain and continually improve its ISMS. It's critical to understand that the ISMS is an ongoing programme which needs constant proactive management and updating.