ISO 27001 Annex A 5.4 Management Responsibilities + Templates

ISO 27001 Annex A 5.4 Management responsibilities

ISO 27001 Management Responsibilities

ISO 27001 Management Responsibilities is an ISO 27001 control that requires management to ensure that people apply information security in line with documented policies and procedures.

It is ensuring that information security is led from the top down.

Key Takeaways

ISO 27001 Annex A 5.4 requires senior management to actively ensure that all personnel follow the organization’s information security policies and procedures. This control shifts security from being “the IT department’s problem” to a top-down leadership mandate. The goal is to ensure that management understands their role in fostering a security culture and provides the necessary resources, oversight, and legal frameworks to enforce data protection standards across the entire workforce.

  • Leaders are responsible for making sure everyone follows the security rules.
  • Companies need to train their staff so they know their part in keeping information safe.
  • Clear security policies and job duties should be written down for all to see.

Purpose

The purpose of Annex A 5.4 is to ensure management understand their role in information security and undertake actions aiming to ensure all personnel are aware of and fulfil their information security responsibilities.

Definition

The ISO 27001 standard defines ISO 27001 Management Responsibilities as:

Management should require all personnel to apply information security in accordance with the established information security policy, topic-specific policies and procedures of the organization.

ISO 27001 Annex A 5.4 Management Responsibilities

Explanation

ISO 27001 Annex A 5.4 Management Responsibilities is a security control that requires senior leadership to mandate information security policy adherence. The primary implementation requirement is a top-down governance framework where management provides resources and enforces accountability, delivering the business benefit of a robust, leadership-driven security culture across the workforce.

Requirement

  • Mandated Compliance: Management must require all staff and contractors to apply information security in accordance with established policies. This isn’t optional; it must be a condition of employment.
  • Resource Allocation: Leaders must provide adequate resources (budget, time, and tools) to implement and maintain the Information Security Management System (ISMS).
  • Competence & Skills: Management is responsible for ensuring that personnel are competent for their security roles. This involves maintaining a Competency Matrix to track training, experience, and certifications.
  • Contractual Enforcement: Security requirements must be explicitly stated in employment contracts and third-party agreements to ensure they are legally enforceable.
  • Whistleblowing Process: Management must implement a process that allows employees to report security concerns or violations anonymously and without fear of retaliation.

Audit Focus

  1. Direct Evidence: “Show me the meeting minutes where senior management reviewed the risk register and approved the security budget.”
  2. The Whistleblower Test: “If an employee sees a manager bypassing security rules, how do they report it? Show me the documented process.”
  3. Policy Acknowledgement: They will check if all new hires, including senior executives, have signed their employment contracts and completed their initial security training.

FREE Training Video

In this free training video you will learn How to Implement ISO 27001 Management Responsibilities (Annex A 5.4) and Pass Your Audit

Implementation Guide

You are going to have to ensure that:

  • information security roles and responsibilities are documented and people are briefed on them before they get access to information
  • guidelines for information security expectations are in place and they are shared with people
  • information security policies are in place and people are aware that they are mandated
  • implement information security training and awareness relevant to people’s roles
  • have terms and conditions of employment, contracts or agreements that include information security and relate to the policies
  • information security skills and qualifications where relevant are ongoing
  • you have a whistleblowing process
  • adequate resources are made available for information security related controls and processes.

ISO 27001 Templates

Fast track your ISO 27001 build with the ISO 27001 Templates Pack.

ISO 27001 Templates - ISO 27001 Annex A 5.2 Information Security Roles and Responsibilities Templates
ISO 27001 Templates

ISO 27001 Policies

To act in accordance with ISO 27001 information security policies and procedures you first need to implement them. Follow the guidance in The Ultimate Guide to ISO 27001 Annex A 5.1 Policies for Information Security

Roles and Responsibilities

It is straight forward to document the roles and responsibilities. Start with defining what the roles are. You state the name of the role and then list what the role is responsible for in terms of information security.

Example Information Security Roles

Typical roles that are required include, but is certainly not limited to:

  • CEO
  • Leadership
  • Information Security Management Leadership
  • Information Security Manager
  • Management Review Team
  • Third Party Supplier Manager
  • Business Continuity Manager
  • Information Owners
  • Information Security Incident Management

Example Information Security Responsibilities

An example of information security responsibilities assigned to a role would be the role of the CEO. Let’s take a look:

CEO

  • Sets the company direction for information security
  • Promotes a culture of information security aligned to the business objectives
  • Signs off and agrees on resources, objectives, risks and risk treatment

Competence

Once people are assigned then we are going to record and manage their competence to perform the role. Usually this is a measure of experience and training. You are going to create and maintain an ISO 27001 Competency Matrix.

The Role of HR

You have a reliance on HR. There are many HR process that will come into play throughout the implementation, including on boarding new employees, off boarding when people leave, disciplinary processes and more. Specific to this particular clause you are going to have terms and conditions of employment, contracts or agreements that include information security and relate to the policies. You are going to work to ensure that information security is part of all HR process as appropriate.

Communication and Training

A large part of this control is communication and training. Actually telling people what is expected of them. Having a communication plan in place that covers what you will communicate, when, to whom and how is a great way to set a structure for the year. Telling people where policies are, how to report incidents, who they can speak to about information security are some of the basics. Alongside this you will have training on a range of topics and requirements – you can learn more in The Ultimate Guide to ISO 27001 Annex A 6.3 Information Security Awareness, Education and Training

Manager’s Monthly Checklist Example

ActionWhy?Evidence
Brief TeamRemind staff of policies (e.g., locking screens).Meeting Minutes.
Check ComplianceVerify staff completed security training.Training Log.
Enforce RulesCorrect bad behavior (e.g., password sharing).Disciplinary Note / Email.
Lead by ExampleWear ID badge visible at all times.Visual Observation (Audit).

ISO 27001 Roles and Responsibilities Template

The Documented Roles and Responsibilities Template has the roles already defined with the responsibilities already written.

ISO 27001 Annex A 5.2 Information Security Roles and Responsibilities Template - ISO 27001 Annex A 5.4 Template

ISO 27001 Competency Template

For competency the great ISO 27001 Competency Matrix will get you up to speed fast.

ISO 27001 Competency Matrix Template - ISO 27001 Annex A 5.4 Template

How to implement it

A detailed how to implement ISO 27001 Annex A 5.4 is covered in How to Implement ISO 27001 Annex A 5.4

How to audit it

A detailed how to audit ISO 27001 Annex A 5.4 is covered How to Audit ISO 27001 Annex A 5.4

Audit Checklist

For an audit checklist to ISO 27001 Annex A 5.4 read ISO 27001 Annex A 5.4 Management Responsibilities Audit Checklist.

How to comply

To comply with ISO 27001 Annex A 5.4 you are going to implement the ‘how’ to the ‘what’ the control is expecting. In short measure you are going to:

Summary: For Annex A 5.4, the auditor wants to see that management is actively involved and that people are held accountable for security responsibilities. The High Table ISO 27001 Toolkit provides the governance framework to satisfy this requirement immediately. It is the most direct, cost-effective way to achieve compliance using permanent documentation that you own and control.

How to pass the audit

To pass an audit of ISO 27001 Annex A 5.4 Management Responsibilities you are going to make sure that you have followed the steps above in how to comply.

Top 3 Mistakes and How to Fix Them

In my experience, the top 3 mistakes people make for ISO 27001 Annex A 5.4 Management Responsibilities are:

  1. You have no contracts in place: You need to have contracts in place and they need to include relevant information security requirements. This can often be overlooked or the contracts that you have can be out of date. It is a good idea to check before the audit.
  2. One or more members of your team haven’t done what they should have done: Prior to the audit check that all members of the team have done what they should have. Do they know where the policies are? Have they acknowledged them? Did someone join last month and forget to do it? Check!
  3. Your document and version control is wrong: Keeping your document version control up to date, making sure that version numbers match where used, having a review evidenced in the last 12 months, having documents that have no comments in are all good practices.
Industry Standard / LawRelevant Section / RequirementMapping to Management Responsibilities (A.5.4)
NIST SP 800-53 (Rev. 5)PL-4 (Rules of Behaviour) & PM-10Management must establish and sign “Rules of Behaviour.” Mirrors A.5.4’s requirement for management to mandate policy adherence.
NIS2 Directive (EU)Article 20 (Governance)Mandates that “management bodies” approve and oversee risk management. Introduces personal liability for senior leaders for non-compliance.
DORA (EU)Article 5 (Governance)Places “ultimate responsibility” on the Board for ICT risk. Management must ensure staff are trained and roles are executed as defined in the ICT strategy.
SOC2 (AICPA)CC1.3 (COSO Principle 3)Management must establish “Tone at the Top” and hold individuals accountable for their internal control responsibilities.
UK Data (Use & Access) Act 2025Governance & Accountability ReformsWhile reducing “paperwork”, it requires management to justify “Recognised Legitimate Interests” and ensure high security thresholds for automated decision-making.
UK Cyber Security & Resilience BillMSPs & Senior LiabilityExpands reporting duties for Managed Service Providers. Management must ensure personnel are “competent” (often mapped to UK Cyber Security Council titles).
CIRCIA (USA)Reporting GovernanceRequires management to ensure staff are capable of identifying and reporting “covered incidents” to CISA within 72 hours.
EU Product Liability Directive (PLD)Strict Liability for SoftwareManagement is strictly liable for cybersecurity flaws in software. Requires management oversight of the entire product lifecycle to ensure “safety-relevant” security.
ECCF (EU Certification)Harmonised Security LabelsManagement must attest to the “Self-Assessment” or “Third-Party” certification levels (Basic, Substantial, High) for products and services.
EU AI ActArticle 17 (Quality Management)Providers of High-Risk AI must implement a QMS where management is accountable for data quality, human oversight, and post-market monitoring.
ISO/IEC 42001 (AI Management)Clause 5.1 (Leadership)Direct alignment. Management must provide resources and ensure AI security objectives are integrated into business processes.
GDPR (EU/UK)Article 5(2) & 24The “Accountability Principle.” Management must demonstrate they have implemented appropriate technical and organisational measures.
HIPAA (USA)45 CFR § 164.308 (Admin Safeguards)Requires a “Security Management Process” including Sanction Policies (A.5.4’s disciplinary requirement) and assigned security responsibility.
CCPA / CPRA (California)Section 1798.100 (Governance)Requires management to assign a “team or individual” responsible for privacy and perform annual risk assessments/audits.

Applicability across different business models

Business TypeApplicability & InterpretationExamples of Control
Small Businesses

Tone from the Top. In a small team, if the owner bypasses security (e.g., sharing passwords), everyone else will too. Compliance requires management to lead by example, not just sign a policy.

The “CEO Training” Rule: Ensuring the Managing Director completes the same cybersecurity awareness training as the newest intern. • Visible Enforcement: The owner actively using the company Password Manager during team meetings to demonstrate it is mandatory.

Tech Startups

Culture over Compliance. Management responsibility isn’t just about the CISO; it’s about Engineering Leads enforcing secure coding standards. It prevents “Security” from becoming a blocker to “Shipping.”

Blocker Authority: Empowering Engineering Managers to block a release if security checks fail, proving that safety outranks speed. • Resource Allocation: Explicitly budgeting developer hours in the sprint for “Security Debt” repayment, authorized by the CTO.

AI Companies

Ethical Oversight. Management must take responsibility for the safety of the models they release. This goes beyond data security into AI alignment and preventing misuse.

Model Sign-off: A “Go/No-Go” release meeting where the Head of Research must sign off on the safety report before a model is deployed. • Whistleblowing Channels: Establishing a clear, anonymous channel for researchers to report safety concerns about model behavior directly to the Board.

Mapped to other Standards and Laws

Framework / RegulationRelevant Control or SectionMapping to Management Responsibilities (Annex A 5.4)
NIST SP 800-53 (Rev 5)PL-4 (Rules of Behavior) PM-10 (Security Authorization Process)Direct equivalence. NIST PL-4 requires management to establish and sign rules of behaviour, mirroring the A.5.4 requirement for personnel to apply security in accordance with established policy.
EU NIS 2 DirectiveArticle 20 (Governance) Article 21 (Risk Management Measures)NIS 2 Article 20 mandates that “management bodies” approve and oversee cybersecurity measures. Annex A 5.4 provides the operational evidence (staff adherence) required to satisfy this governance obligation.
EU DORAArticle 5 (Governance and Organisation)DORA explicitly places “ultimate responsibility” on the management body. Implementing A.5.4 ensures that the roles and strategies defined by the Board under Article 5 are actually executed by staff.
UK Cyber Security & Resilience BillSenior Management Liability (Pending Legislation)Expected to mirror NIS 2, this Bill introduces personal liability for senior managers. A.5.4 compliance is the primary defence mechanism, demonstrating that management actively enforced security policies rather than just documenting them.
SOC 2 (AICPA)CC1.3 (COSO Principle 3) CC5.3 (Risk Mitigation)SOC 2 requires management to establish “tone at the top”. Auditors test A.5.4 by verifying if management holds individuals accountable for internal control responsibilities.
CIRCIA (USA)Reporting Governance (CISA Reporting Requirements)Mandates 72-hour reporting for critical infrastructure. A.5.4 is essential here: management must ensure staff are trained and obligated to report incidents immediately to meet this federal deadline.
EU Product Liability Directive (PLD)Strict Liability for Software (Defectiveness)The PLD extends strict liability to software defects, including security flaws. Management responsibilities (A.5.4) now extend to ensuring developers follow “Security by Design” principles to prevent liability claims.
UK Data (Use and Access) Act 2025Accountability Principle (Amended UK GDPR)While reducing some administrative burdens (e.g., simplified ROPA), the Act maintains strict accountability. A.5.4 ensures that staff understand and apply the new “Recognised Legitimate Interests” for data processing correctly.
EU AI ActArticle 4 (AI Literacy) Article 9 (Risk Management)Management must ensure personnel are competent in using AI systems (Article 4). A.5.4 enforces the usage policies required to prevent “High-Risk” AI systems from drifting into non-compliance.
HIPAA (USA)§ 164.308(a)(1) (Security Management Process)Requires covered entities to implement policies and procedures. A.5.4 is the “Administrative Safeguard” that ensures the workforce actually complies with these HIPAA sanctions policies.
ECCFCyber Resilience Act (CRA) LinksFor EU-wide certification, management must affirm that processes are followed. A.5.4 provides the internal audit trail required to achieve “Substantial” or “High” assurance levels under the framework.

FAQ

Is a formal disciplinary process mandatory for Annex A 5.4?

Yes, management must establish, communicate, and maintain a formalised disciplinary process to handle employees who violate security policies.

What is the difference between Clause 5 and Annex A 5.4?

While Clause 5 focuses on high-level leadership and the overall ISMS strategy, Annex A 5.4 is an operational control focused on management’s role in enforcing policy adherence among staff.

How can management demonstrate commitment to ISO 27001?

Management demonstrates commitment by integrating security into business processes and ensuring that security objectives are aligned with organisational goals.

ISO 27001 Controls and Attribute Values

Control typeInformation
security properties
Cybersecurity
concepts
Operational
capabilities
Security domains
PreventiveConfidentialityIdentifyGovernanceGovernance and Ecosystem
Integrity
Availability

About the author

Stuart Barker
🎓 MSc Security 🛡️ Lead Auditor 30+ Years Exp 🏢 Ex-GE Leader

Stuart Barker

ISO 27001 Ninja

Stuart Barker is a veteran practitioner with over 30 years of experience in systems security and risk management. Holding an MSc in Software and Systems Security, he combines academic rigor with extensive operational experience, including a decade leading Data Governance for General Electric (GE).

As a qualified ISO 27001 Lead Auditor, Stuart possesses distinct insight into the specific evidence standards required by certification bodies. His toolkits represent an auditor-verified methodology designed to minimise operational friction while guaranteeing compliance.

ISO 27001 Annex A 5.4 Management responsibilities
Shopping Basket
Scroll to Top