Our own servers in Europe · GDPR · Support in your language

Module 2 of 7 · ISO 27001 · Clause 5

Leadership

Management must build information security into business strategy and assign clear responsibilities, not delegate it entirely to IT.

Content reviewed on

Demonstrated commitment and leadership

Management ensures the security policy and objectives are compatible with the organization's strategic direction.

Information security policy

It must include a commitment to meet applicable security requirements and to continually improve the ISMS.

Roles, responsibilities and authorities

Management assigns who is accountable for ISMS conformity and for reporting on its performance, including the owner of each risk.

What an auditor usually asks for

  • A security policy that is signed, communicated and understood by staff
  • Management review minutes focused on information security
  • An ISMS responsibility matrix, including risk owners
  • Evidence that management allocates resources to the system

How to cover leadership in Kimobox

  1. 1Publish the security policy as a controlled document, with a read receipt.
  2. 2Assign an owner to each risk and each asset directly in the system.
  3. 3Turn management review into a template with security incidents already pre-loaded.

Management review pulls in the period's security incidents without assembling a separate report.

See Kimobox's quality portal

Where each figure comes from

References to the official text in force. If a standard is revised, this page is updated and the review date says so.

  1. ISO/IEC 27001:2022 — Information security management systems ISO/IEC · 25 October 2022
  2. ISO/IEC 27002:2022 — Information security controls ISO/IEC · February 2022
  3. Directive (EU) 2022/2555 (NIS2) EUR-Lex · Transposition deadline: 17 October 2024