ISO 27001 Management Responsibilities
ISO 27001 Management Responsibilities is an ISO 27001 control that requires management to ensure that people apply information security in line with documented policies and procedures.
It is ensuring that information security is led from the top down.
Table of contents
- ISO 27001 Management Responsibilities
- Key Takeaways
- Purpose
- Definition
- Explanation
- Requirement
- Audit Focus
- FREE Training Video
- Implementation Guide
- ISO 27001 Templates
- ISO 27001 Policies
- Roles and Responsibilities
- Competence
- The Role of HR
- Communication and Training
- Manager’s Monthly Checklist Example
- ISO 27001 Roles and Responsibilities Template
- ISO 27001 Competency Template
- How to implement it
- How to audit it
- Audit Checklist
- How to comply
- How to pass the audit
- Top 3 Mistakes and How to Fix Them
- Applicable Laws and Related Standards
- Applicability across different business models
- Mapped to other Standards and Laws
- FAQ
- ISO 27001 Controls and Attribute Values
Key Takeaways
ISO 27001 Annex A 5.4 requires senior management to actively ensure that all personnel follow the organization’s information security policies and procedures. This control shifts security from being “the IT department’s problem” to a top-down leadership mandate. The goal is to ensure that management understands their role in fostering a security culture and provides the necessary resources, oversight, and legal frameworks to enforce data protection standards across the entire workforce.
- Leaders are responsible for making sure everyone follows the security rules.
- Companies need to train their staff so they know their part in keeping information safe.
- Clear security policies and job duties should be written down for all to see.
Purpose
The purpose of Annex A 5.4 is to ensure management understand their role in information security and undertake actions aiming to ensure all personnel are aware of and fulfil their information security responsibilities.
Definition
The ISO 27001 standard defines ISO 27001 Management Responsibilities as:
Management should require all personnel to apply information security in accordance with the established information security policy, topic-specific policies and procedures of the organization.
ISO 27001 Annex A 5.4 Management Responsibilities
Explanation
ISO 27001 Annex A 5.4 Management Responsibilities is a security control that requires senior leadership to mandate information security policy adherence. The primary implementation requirement is a top-down governance framework where management provides resources and enforces accountability, delivering the business benefit of a robust, leadership-driven security culture across the workforce.
Requirement
- Mandated Compliance: Management must require all staff and contractors to apply information security in accordance with established policies. This isn’t optional; it must be a condition of employment.
- Resource Allocation: Leaders must provide adequate resources (budget, time, and tools) to implement and maintain the Information Security Management System (ISMS).
- Competence & Skills: Management is responsible for ensuring that personnel are competent for their security roles. This involves maintaining a Competency Matrix to track training, experience, and certifications.
- Contractual Enforcement: Security requirements must be explicitly stated in employment contracts and third-party agreements to ensure they are legally enforceable.
- Whistleblowing Process: Management must implement a process that allows employees to report security concerns or violations anonymously and without fear of retaliation.
Audit Focus
- Direct Evidence: “Show me the meeting minutes where senior management reviewed the risk register and approved the security budget.”
- The Whistleblower Test: “If an employee sees a manager bypassing security rules, how do they report it? Show me the documented process.”
- Policy Acknowledgement: They will check if all new hires, including senior executives, have signed their employment contracts and completed their initial security training.
FREE Training Video
In this free training video you will learn How to Implement ISO 27001 Management Responsibilities (Annex A 5.4) and Pass Your Audit
Implementation Guide
You are going to have to ensure that:
- information security roles and responsibilities are documented and people are briefed on them before they get access to information
- guidelines for information security expectations are in place and they are shared with people
- information security policies are in place and people are aware that they are mandated
- implement information security training and awareness relevant to people’s roles
- have terms and conditions of employment, contracts or agreements that include information security and relate to the policies
- information security skills and qualifications where relevant are ongoing
- you have a whistleblowing process
- adequate resources are made available for information security related controls and processes.
ISO 27001 Templates
Fast track your ISO 27001 build with the ISO 27001 Templates Pack.

ISO 27001 Policies
To act in accordance with ISO 27001 information security policies and procedures you first need to implement them. Follow the guidance in The Ultimate Guide to ISO 27001 Annex A 5.1 Policies for Information Security
Roles and Responsibilities
It is straight forward to document the roles and responsibilities. Start with defining what the roles are. You state the name of the role and then list what the role is responsible for in terms of information security.
Example Information Security Roles
Typical roles that are required include, but is certainly not limited to:
- CEO
- Leadership
- Information Security Management Leadership
- Information Security Manager
- Management Review Team
- Third Party Supplier Manager
- Business Continuity Manager
- Information Owners
- Information Security Incident Management
Example Information Security Responsibilities
An example of information security responsibilities assigned to a role would be the role of the CEO. Let’s take a look:
CEO
- Sets the company direction for information security
- Promotes a culture of information security aligned to the business objectives
- Signs off and agrees on resources, objectives, risks and risk treatment
Competence
Once people are assigned then we are going to record and manage their competence to perform the role. Usually this is a measure of experience and training. You are going to create and maintain an ISO 27001 Competency Matrix.
The Role of HR
You have a reliance on HR. There are many HR process that will come into play throughout the implementation, including on boarding new employees, off boarding when people leave, disciplinary processes and more. Specific to this particular clause you are going to have terms and conditions of employment, contracts or agreements that include information security and relate to the policies. You are going to work to ensure that information security is part of all HR process as appropriate.
Communication and Training
A large part of this control is communication and training. Actually telling people what is expected of them. Having a communication plan in place that covers what you will communicate, when, to whom and how is a great way to set a structure for the year. Telling people where policies are, how to report incidents, who they can speak to about information security are some of the basics. Alongside this you will have training on a range of topics and requirements – you can learn more in The Ultimate Guide to ISO 27001 Annex A 6.3 Information Security Awareness, Education and Training
Manager’s Monthly Checklist Example
| Action | Why? | Evidence |
| Brief Team | Remind staff of policies (e.g., locking screens). | Meeting Minutes. |
| Check Compliance | Verify staff completed security training. | Training Log. |
| Enforce Rules | Correct bad behavior (e.g., password sharing). | Disciplinary Note / Email. |
| Lead by Example | Wear ID badge visible at all times. | Visual Observation (Audit). |
ISO 27001 Roles and Responsibilities Template
The Documented Roles and Responsibilities Template has the roles already defined with the responsibilities already written.

ISO 27001 Competency Template
For competency the great ISO 27001 Competency Matrix will get you up to speed fast.

How to implement it
A detailed how to implement ISO 27001 Annex A 5.4 is covered in How to Implement ISO 27001 Annex A 5.4
How to audit it
A detailed how to audit ISO 27001 Annex A 5.4 is covered How to Audit ISO 27001 Annex A 5.4
Audit Checklist
For an audit checklist to ISO 27001 Annex A 5.4 read ISO 27001 Annex A 5.4 Management Responsibilities Audit Checklist.
How to comply
To comply with ISO 27001 Annex A 5.4 you are going to implement the ‘how’ to the ‘what’ the control is expecting. In short measure you are going to:
- Document your information security roles and responsibilities
- Implement a program of Information Security Training and Awareness and maintain a Communication Plan
- Implement Information Security Management Policies
- Engage a HR specialist to ensure your HR documentation is legal and meets HR best practice
- Ensure you have contracts in place with all staff, contractors and third parties
- Maintain a competency matrix to track the skills and qualifications of staff
- Implement a whistleblowing process
- Free people’s time to work on information security or bring in specialist help
Summary: For Annex A 5.4, the auditor wants to see that management is actively involved and that people are held accountable for security responsibilities. The High Table ISO 27001 Toolkit provides the governance framework to satisfy this requirement immediately. It is the most direct, cost-effective way to achieve compliance using permanent documentation that you own and control.
How to pass the audit
To pass an audit of ISO 27001 Annex A 5.4 Management Responsibilities you are going to make sure that you have followed the steps above in how to comply.
Fast track your ISO 27001 build with the ISO 27001 Templates Pack.
Top 3 Mistakes and How to Fix Them
In my experience, the top 3 mistakes people make for ISO 27001 Annex A 5.4 Management Responsibilities are:
- You have no contracts in place: You need to have contracts in place and they need to include relevant information security requirements. This can often be overlooked or the contracts that you have can be out of date. It is a good idea to check before the audit.
- One or more members of your team haven’t done what they should have done: Prior to the audit check that all members of the team have done what they should have. Do they know where the policies are? Have they acknowledged them? Did someone join last month and forget to do it? Check!
- Your document and version control is wrong: Keeping your document version control up to date, making sure that version numbers match where used, having a review evidenced in the last 12 months, having documents that have no comments in are all good practices.
Applicable Laws and Related Standards
| Industry Standard / Law | Relevant Section / Requirement | Mapping to Management Responsibilities (A.5.4) |
|---|---|---|
| NIST SP 800-53 (Rev. 5) | PL-4 (Rules of Behaviour) & PM-10 | Management must establish and sign “Rules of Behaviour.” Mirrors A.5.4’s requirement for management to mandate policy adherence. |
| NIS2 Directive (EU) | Article 20 (Governance) | Mandates that “management bodies” approve and oversee risk management. Introduces personal liability for senior leaders for non-compliance. |
| DORA (EU) | Article 5 (Governance) | Places “ultimate responsibility” on the Board for ICT risk. Management must ensure staff are trained and roles are executed as defined in the ICT strategy. |
| SOC2 (AICPA) | CC1.3 (COSO Principle 3) | Management must establish “Tone at the Top” and hold individuals accountable for their internal control responsibilities. |
| UK Data (Use & Access) Act 2025 | Governance & Accountability Reforms | While reducing “paperwork”, it requires management to justify “Recognised Legitimate Interests” and ensure high security thresholds for automated decision-making. |
| UK Cyber Security & Resilience Bill | MSPs & Senior Liability | Expands reporting duties for Managed Service Providers. Management must ensure personnel are “competent” (often mapped to UK Cyber Security Council titles). |
| CIRCIA (USA) | Reporting Governance | Requires management to ensure staff are capable of identifying and reporting “covered incidents” to CISA within 72 hours. |
| EU Product Liability Directive (PLD) | Strict Liability for Software | Management is strictly liable for cybersecurity flaws in software. Requires management oversight of the entire product lifecycle to ensure “safety-relevant” security. |
| ECCF (EU Certification) | Harmonised Security Labels | Management must attest to the “Self-Assessment” or “Third-Party” certification levels (Basic, Substantial, High) for products and services. |
| EU AI Act | Article 17 (Quality Management) | Providers of High-Risk AI must implement a QMS where management is accountable for data quality, human oversight, and post-market monitoring. |
| ISO/IEC 42001 (AI Management) | Clause 5.1 (Leadership) | Direct alignment. Management must provide resources and ensure AI security objectives are integrated into business processes. |
| GDPR (EU/UK) | Article 5(2) & 24 | The “Accountability Principle.” Management must demonstrate they have implemented appropriate technical and organisational measures. |
| HIPAA (USA) | 45 CFR § 164.308 (Admin Safeguards) | Requires a “Security Management Process” including Sanction Policies (A.5.4’s disciplinary requirement) and assigned security responsibility. |
| CCPA / CPRA (California) | Section 1798.100 (Governance) | Requires management to assign a “team or individual” responsible for privacy and perform annual risk assessments/audits. |
Applicability across different business models
| Business Type | Applicability & Interpretation | Examples of Control |
|---|---|---|
| Small Businesses |
Tone from the Top. In a small team, if the owner bypasses security (e.g., sharing passwords), everyone else will too. Compliance requires management to lead by example, not just sign a policy. |
• The “CEO Training” Rule: Ensuring the Managing Director completes the same cybersecurity awareness training as the newest intern. • Visible Enforcement: The owner actively using the company Password Manager during team meetings to demonstrate it is mandatory. |
| Tech Startups |
Culture over Compliance. Management responsibility isn’t just about the CISO; it’s about Engineering Leads enforcing secure coding standards. It prevents “Security” from becoming a blocker to “Shipping.” |
• Blocker Authority: Empowering Engineering Managers to block a release if security checks fail, proving that safety outranks speed. • Resource Allocation: Explicitly budgeting developer hours in the sprint for “Security Debt” repayment, authorized by the CTO. |
| AI Companies |
Ethical Oversight. Management must take responsibility for the safety of the models they release. This goes beyond data security into AI alignment and preventing misuse. |
• Model Sign-off: A “Go/No-Go” release meeting where the Head of Research must sign off on the safety report before a model is deployed. • Whistleblowing Channels: Establishing a clear, anonymous channel for researchers to report safety concerns about model behavior directly to the Board. |
Mapped to other Standards and Laws
| Framework / Regulation | Relevant Control or Section | Mapping to Management Responsibilities (Annex A 5.4) |
|---|---|---|
| NIST SP 800-53 (Rev 5) | PL-4 (Rules of Behavior) PM-10 (Security Authorization Process) | Direct equivalence. NIST PL-4 requires management to establish and sign rules of behaviour, mirroring the A.5.4 requirement for personnel to apply security in accordance with established policy. |
| EU NIS 2 Directive | Article 20 (Governance) Article 21 (Risk Management Measures) | NIS 2 Article 20 mandates that “management bodies” approve and oversee cybersecurity measures. Annex A 5.4 provides the operational evidence (staff adherence) required to satisfy this governance obligation. |
| EU DORA | Article 5 (Governance and Organisation) | DORA explicitly places “ultimate responsibility” on the management body. Implementing A.5.4 ensures that the roles and strategies defined by the Board under Article 5 are actually executed by staff. |
| UK Cyber Security & Resilience Bill | Senior Management Liability (Pending Legislation) | Expected to mirror NIS 2, this Bill introduces personal liability for senior managers. A.5.4 compliance is the primary defence mechanism, demonstrating that management actively enforced security policies rather than just documenting them. |
| SOC 2 (AICPA) | CC1.3 (COSO Principle 3) CC5.3 (Risk Mitigation) | SOC 2 requires management to establish “tone at the top”. Auditors test A.5.4 by verifying if management holds individuals accountable for internal control responsibilities. |
| CIRCIA (USA) | Reporting Governance (CISA Reporting Requirements) | Mandates 72-hour reporting for critical infrastructure. A.5.4 is essential here: management must ensure staff are trained and obligated to report incidents immediately to meet this federal deadline. |
| EU Product Liability Directive (PLD) | Strict Liability for Software (Defectiveness) | The PLD extends strict liability to software defects, including security flaws. Management responsibilities (A.5.4) now extend to ensuring developers follow “Security by Design” principles to prevent liability claims. |
| UK Data (Use and Access) Act 2025 | Accountability Principle (Amended UK GDPR) | While reducing some administrative burdens (e.g., simplified ROPA), the Act maintains strict accountability. A.5.4 ensures that staff understand and apply the new “Recognised Legitimate Interests” for data processing correctly. |
| EU AI Act | Article 4 (AI Literacy) Article 9 (Risk Management) | Management must ensure personnel are competent in using AI systems (Article 4). A.5.4 enforces the usage policies required to prevent “High-Risk” AI systems from drifting into non-compliance. |
| HIPAA (USA) | § 164.308(a)(1) (Security Management Process) | Requires covered entities to implement policies and procedures. A.5.4 is the “Administrative Safeguard” that ensures the workforce actually complies with these HIPAA sanctions policies. |
| ECCF | Cyber Resilience Act (CRA) Links | For EU-wide certification, management must affirm that processes are followed. A.5.4 provides the internal audit trail required to achieve “Substantial” or “High” assurance levels under the framework. |
FAQ
Yes, management must establish, communicate, and maintain a formalised disciplinary process to handle employees who violate security policies.
While Clause 5 focuses on high-level leadership and the overall ISMS strategy, Annex A 5.4 is an operational control focused on management’s role in enforcing policy adherence among staff.
Management demonstrates commitment by integrating security into business processes and ensuring that security objectives are aligned with organisational goals.
ISO 27001 Controls and Attribute Values
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|---|---|---|---|---|
| Preventive | Confidentiality | Identify | Governance | Governance and Ecosystem |
| Integrity | ||||
| Availability |
About the author
