How to conduct an ISO 27001 Management Review Meeting

Share with your network

Conducting an ISO 27001 Management Review team meeting: a step by step guide

What is an ISO 27001 Management Review Meeting?

ISO 27001 has the concept of leadership buy in built in. It sees information security as being driven from the top down. As part of the management oversight the standard requires a meeting to be conducted on a regular basis that follows a structured and defined agenda. The agenda covers the ongoing operational requirements of the information security standard.

ISO 27001 Management Review Attendees

Who should attend the ISO 27001 Management Review? The attendees of the management review should be:

  • The information security manager
  • A member of the senior leadership team
  • A representative from each department in the business
  • Adhoc resource specific to that meeting as required

When considering the people that attend consider the following roles that are responsible for:

  • Information Security
  • Leadership
  • HR
  • Change Management
  • Operational Management
  • Supplier Management
  • Software Development (if applicable)
  • Information Technology
  • Business Continuity and Disaster Recovery

What is the required agenda of the ISO 27001 Management Review Meeting

The standard sets out specific requirements for what must be covered in the meeting. You can add to this list but as a minimum you should have an agenda that covers:

  • the status of actions from previous management reviews;
  • changes in external and internal issues that are relevant to the information security management system;
  • feedback on the information security performance, including trends in:
  • nonconformities and corrective actions;
  • monitoring and measurement results;
  • audit results; and
  • fulfilment of information security objectives;”
  • feedback from interested parties;
  • results of risk assessment and status of risk treatment plan; and
  • opportunities for continual improvement.
  • The outputs of the management review shall include decisions related to continual improvement opportunities and any needs for changes to the information security management system.

ISO 27001 Clause 9.3 Management Review

Let us take a look at what the ISO 27001 requirement is for a management review before we step through the process of How to conduct a Management Review Team Meeting

The ISO 27001 standard wants us to conduct regular, planned reviews of our information security management system to make sure that everything is working as it should. It is a fundamental part of the management system and as such it actually ticks a few of the ISO 27001 boxes. In particular it is address in ISO 27001 Clause 9.3 Management review and is one of the ISO 27001 mandatory documents.

The output and result of the meeting is a record of decisions made and changes needed. It is a requirement to keep copies of the meetings as evidence. It does have a structure agenda as per the Management Review Team Agenda Template. In brief it covers tracking of objectives, monitoring results, risk management, continual improvement, audit results and feedback.

Top management shall review the organisation’s information security management system at planned intervals to ensure its continuing suitability, adequacy and effectiveness.

The management review shall include consideration of:

a) the status of actions from previous management reviews;
b) changes in external and internal issues that are relevant to the information security management system;
c) feedback on the information security performance, including trends in:
1) nonconformities and corrective actions;
2) monitoring and measurement results;
3) audit results; and
4) fulfilment of information security objectives;”
d) feedback from interested parties;
e) results of risk assessment and status of risk treatment plan; and
f ) opportunities for continual improvement.
The outputs of the management review shall include decisions related to continual improvement opportunities and any needs for changes to the information security management system.
The organisation shall retain documented information as evidence of the results of management reviews.

ISO 27001 Clause 9.3 Management Review

How to conduct an ISO 27001 Management Review Meeting

Time needed: 2 hours and 15 minutes.

How to conduct an ISO 27001 Management Review Meeting

  1. Decide How Often to have a Management Review Meeting

    It is recommended that you have a management review meeting every month. This allows you to effectively manage, especially in the first year of an implementation. It is suggested that no less than every 3 months being at least 4 meetings a year.

  2. Book Your Meeting(s)

    It is good practice to set your meetings at the beginning of the year.
    Be sure to book your meeting several weeks in advance to ensure availability. 
    Meetings can be conducted remotely over web collaboration tools such as Zoom, or Teams or meetings can be booked face to face in a meeting room.
    If you book a meeting room, make sure that the room has a display screen that can be seen by all attendees. 

  3. Meeting Duration

    Book a 1-hour meeting slot. On average a Management Review Meeting will take around 45 minutes. In time as you establish your information security management system and operating rhythm this time will reduce. If you over run additional meetings can be booked. 

  4. Prepare for the Management Review Meeting

    Create a sub folder in your document storage for the meeting.
    Collate the latest copies of the required documents for the Management Review Meeting and place them in the sub folder.
    Ahead of the meeting, suggest 5 working days in advance, share links to the latest version of the documents with the invitees.
    Note: confidential documents that should not be shared via email.
    Consider your audience and the format they want to see the documents. You may require print outs, although this is discouraged. If required prepare them in advance.
    Ensure that all of the documents are up to date and that all previous actions are updated.
    Ensure people know if they are due to report back what is expected and in what format. 

  5. Create your agenda

    Use the agenda template ‘Management Review Team Agenda – Template
    Complete the agenda and update the relevant sections.

  6. Send the Invite to the Management Review Team

    The Management Review Team are documented in the document Roles and Responsibilities. If not already sent, send the invite to the management review team and any guest attendees.
    If the Management Review Team has changed update the document Roles and Responsibilities, remembering to update the version control.

  7. Run The Meeting

    The meeting requires a chairperson for the meeting. Decide on who will chair the meeting. The default is The Information Security Manager.
    The meeting requires minuting. Decide on who will minute the meeting. The default is The Information Security Manager.
    Work through the defined and structured agenda.
    Agree / confirm the date of the next Management Review Meeting.  

  8. Send out the minutes

    Within 5 working days send out links to the meeting minutes to all attendees. 

  9. Update Documents

    Update appropriate management documentation based on the outcomes from the meeting. Documents to consider are 
    Action Log
    Incident and Corrective Action Log
    Risk Register

ISO 27001 Management Review Meeting Agenda Template

The management review meeting agenda template has all of the agenda items required by ISO 27001 Clause 9.3

It has been prewritten to save you time and can be used straight away.

ISO 27001 Management Review Meeting FAQ

Is a Management Review Meeting mandatory?

Yes. Management Review Meetings are Mandatory

What is ISO 27001 Clause 9.3?

ISO 27001 Clause 9.3 is Management review

How often should you do a Management Review Meeting?

A management review meeting should be held at least once every 3 months but ideally once every month.

What is the point in a Management Review meeting?

A management review meeting is a mandatory requirement of the ISO 27001 standard. The meeting has a structured agenda, dictated by the standard, and must cover key topics. It provides management oversight and demonstrates leadership commitment and leadership buy in. It can act as an oversight body to provide sign off on documents and decisions in relation to the management system.

Where do I find a Management Review Meeting agenda template?

A management review meeting agenda template can be downloaded here: https://hightable.io/product/iso-27001-management-review-template/

Who attends the management review meeting?

The management review meeting is attended by the management review team. The management review team is an oversight structure made up of representatives from the business and at least one member of senior leadership. It has set responsibilities as recorded in the Assigned Roles and Responsibilities document. Additional attendees include subject matter experts required for particular agenda items on that particular agenda as required.

Is the Management Review Meeting minuted?

Yes. Minutes are taken and recorded of the meeting. Those meeting minutes are required to be retained as evidence the meetings took place by the standard.

How long is a management review meeting?

ISO 27001 Management Review Meetings should be booked for 1 hour. They can last between 15 minutes and 1 hour depending on how frequently you hold them.

Share with your network
ISO 27001 Templates Toolkit Business Edition Black
ISO27001 Policy Templates Pack Green
Free ISO27001 Strategy Call

Leave a Comment

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Shopping Cart