Conducting an ISO 27001 Management Review team meeting: a step by step guide with template
Table of contents
- What is an ISO 27001 Management Review Meeting?
- ISO 27001 Management Review Attendees
- What is the required agenda of the ISO 27001 Management Review Meeting
- ISO 27001 Management Review Meeting Agenda Template
- ISO 27001 Clause 9.3 Management Review
- How to conduct an ISO 27001 Management Review Meeting
- ISO 27001 Management Review Meeting FAQ
What is an ISO 27001 Management Review Meeting?
ISO 27001 has the concept of leadership buy in built in. It sees information security as being driven from the top down. As part of the management oversight the standard requires a meeting to be conducted on a regular basis that follows a structured and defined agenda. The agenda covers the ongoing operational requirements of the information security standard.
ISO 27001 Management Review Attendees
Who should attend the ISO 27001 Management Review? The attendees of the management review should be:
- The information security manager
- A member of the senior leadership team
- A representative from each department in the business
- Adhoc resource specific to that meeting as required
When considering the people that attend consider the following roles that are responsible for:
- Information Security
- Change Management
- Operational Management
- Supplier Management
- Software Development (if applicable)
- Information Technology
- Business Continuity and Disaster Recovery
What is the required agenda of the ISO 27001 Management Review Meeting
The standard sets out specific requirements for what must be covered in the meeting. You can add to this list but as a minimum you should have an agenda that covers:
- the status of actions from previous management reviews;
- changes in external and internal issues that are relevant to the information security management system;
- feedback on the information security performance, including trends in:
- nonconformities and corrective actions;
- monitoring and measurement results;
- audit results; and
- fulfilment of information security objectives;”
- feedback from interested parties;
- results of risk assessment and status of risk treatment plan; and
- opportunities for continual improvement.
- The outputs of the management review shall include decisions related to continual improvement opportunities and any needs for changes to the information security management system.
ISO 27001 Management Review Meeting Agenda Template
The management review meeting agenda template has all of the agenda items required by ISO 27001 Clause 9.3
It has been prewritten to save you time and can be used straight away.
DO IT YOURSELF ISO27001
STOP SPANKING £10,000s
ISO 27001 Clause 9.3 Management Review
Let us take a look at what the ISO 27001 requirement is for a management review before we step through the process of How to conduct a Management Review Team Meeting
The ISO 27001 standard wants us to conduct regular, planned reviews of our information security management system to make sure that everything is working as it should. It is a fundamental part of the management system and as such it actually ticks a few of the ISO 27001 boxes. In particular it is address in ISO 27001 Clause 9.3 Management review and is one of the ISO 27001 mandatory documents.
The output and result of the meeting is a record of decisions made and changes needed. It is a requirement to keep copies of the meetings as evidence. It does have a structure agenda as per the Management Review Team Agenda Template. In brief it covers tracking of objectives, monitoring results, risk management, continual improvement, audit results and feedback.
Top management shall review the organisation’s information security management system at planned intervals to ensure its continuing suitability, adequacy and effectiveness.
The management review shall include consideration of:
a) the status of actions from previous management reviews;ISO 27001 Clause 9.3 Management Review
b) changes in external and internal issues that are relevant to the information security management system;
c) feedback on the information security performance, including trends in:
1) nonconformities and corrective actions;
2) monitoring and measurement results;
3) audit results; and
4) fulfilment of information security objectives;”
d) feedback from interested parties;
e) results of risk assessment and status of risk treatment plan; and
f ) opportunities for continual improvement.
The outputs of the management review shall include decisions related to continual improvement opportunities and any needs for changes to the information security management system.
The organisation shall retain documented information as evidence of the results of management reviews.
How to conduct an ISO 27001 Management Review Meeting
Time needed: 2 hours and 15 minutes
How to conduct an ISO 27001 Management Review Meeting
- Decide How Often to have a Management Review Meeting
It is recommended that you have a management review meeting every month. This allows you to effectively manage, especially in the first year of an implementation. It is suggested that no less than every 3 months being at least 4 meetings a year.
- Book Your Meeting(s)
It is good practice to set your meetings at the beginning of the year.
Be sure to book your meeting several weeks in advance to ensure availability.
Meetings can be conducted remotely over web collaboration tools such as Zoom, or Teams or meetings can be booked face to face in a meeting room.
If you book a meeting room, make sure that the room has a display screen that can be seen by all attendees.
- Meeting Duration
Book a 1-hour meeting slot. On average a Management Review Meeting will take around 45 minutes. In time as you establish your information security management system and operating rhythm this time will reduce. If you over run additional meetings can be booked.
- Prepare for the Management Review Meeting
Create a sub folder in your document storage for the meeting.
Collate the latest copies of the required documents for the Management Review Meeting and place them in the sub folder.
Ahead of the meeting, suggest 5 working days in advance, share links to the latest version of the documents with the invitees.
Note: confidential documents that should not be shared via email.
Consider your audience and the format they want to see the documents. You may require print outs, although this is discouraged. If required prepare them in advance.
Ensure that all of the documents are up to date and that all previous actions are updated.
Ensure people know if they are due to report back what is expected and in what format.
- Create your agenda
Use the agenda template ‘Management Review Team Agenda – Template’
Complete the agenda and update the relevant sections.
- Send the Invite to the Management Review Team
The Management Review Team are documented in the document Roles and Responsibilities. If not already sent, send the invite to the management review team and any guest attendees.
If the Management Review Team has changed update the document Roles and Responsibilities, remembering to update the version control.
- Run The Meeting
The meeting requires a chairperson for the meeting. Decide on who will chair the meeting. The default is The Information Security Manager.
The meeting requires minuting. Decide on who will minute the meeting. The default is The Information Security Manager.
Work through the defined and structured agenda.
Agree / confirm the date of the next Management Review Meeting.
- Send out the minutes
Within 5 working days send out links to the meeting minutes to all attendees.
- Update Documents
Update appropriate management documentation based on the outcomes from the meeting. Documents to consider are
Incident and Corrective Action Log
ISO 27001 Management Review Meeting FAQ
Yes. Management Review Meetings are Mandatory
ISO 27001 Clause 9.3 is Management review
A management review meeting should be held at least once every 3 months but ideally once every month.
A management review meeting is a mandatory requirement of the ISO 27001 standard. The meeting has a structured agenda, dictated by the standard, and must cover key topics. It provides management oversight and demonstrates leadership commitment and leadership buy in. It can act as an oversight body to provide sign off on documents and decisions in relation to the management system.
An ISO 27001 management review meeting agenda template can be downloaded here.
The management review meeting is attended by the management review team. The management review team is an oversight structure made up of representatives from the business and at least one member of senior leadership. It has set responsibilities as recorded in the Assigned Roles and Responsibilities document. Additional attendees include subject matter experts required for particular agenda items on that particular agenda as required.
Yes. Minutes are taken and recorded of the meeting. Those meeting minutes are required to be retained as evidence the meetings took place by the standard.
ISO 27001 Management Review Meetings should be booked for 1 hour. They can last between 15 minutes and 1 hour depending on how frequently you hold them.