ISO 27001 Annex A 5.4 Management Responsibilities Explained

Stuart And Fay High Table

ISO 27001 Management Responsibilities

ISO 27001 Management Responsibilities is an ISO 27001 control that requires management to ensure that people apply information security in line with documented policies and procedures.

It is ensuring that information security is led from the top down.

Key Takeaways

ISO 27001 Annex A 5.4 requires senior management to actively ensure that all personnel follow the organization’s information security policies and procedures. This control shifts security from being “the IT department’s problem” to a top-down leadership mandate. The goal is to ensure that management understands their role in fostering a security culture and provides the necessary resources, oversight, and legal frameworks to enforce data protection standards across the entire workforce.

  • Leaders are responsible for making sure everyone follows the security rules.
  • Companies need to train their staff so they know their part in keeping information safe.
  • Clear security policies and job duties should be written down for all to see.

Purpose

The purpose of Annex A 5.4 is to ensure management understand their role in information security and undertake actions aiming to ensure all personnel are aware of and fulfil their information security responsibilities.

Definition

The ISO 27001 standard defines ISO 27001 Management Responsibilities as:

Management should require all personnel to apply information security in accordance with the established information security policy, topic-specific policies and procedures of the organization.

ISO 27001 Annex A 5.4 Management Responsibilities

Explanation

ISO 27001 Annex A 5.4 Management Responsibilities is a security control that requires senior leadership to mandate information security policy adherence. The primary implementation requirement is a top-down governance framework where management provides resources and enforces accountability, delivering the business benefit of a robust, leadership-driven security culture across the workforce.

Requirement

  • Mandated Compliance: Management must require all staff and contractors to apply information security in accordance with established policies. This isn’t optional; it must be a condition of employment.
  • Resource Allocation: Leaders must provide adequate resources (budget, time, and tools) to implement and maintain the Information Security Management System (ISMS).
  • Competence & Skills: Management is responsible for ensuring that personnel are competent for their security roles. This involves maintaining a Competency Matrix to track training, experience, and certifications.
  • Contractual Enforcement: Security requirements must be explicitly stated in employment contracts and third-party agreements to ensure they are legally enforceable.
  • Whistleblowing Process: Management must implement a process that allows employees to report security concerns or violations anonymously and without fear of retaliation.

Audit Focus

  1. Direct Evidence: “Show me the meeting minutes where senior management reviewed the risk register and approved the security budget.”
  2. The Whistleblower Test: “If an employee sees a manager bypassing security rules, how do they report it? Show me the documented process.”
  3. Policy Acknowledgement: They will check if all new hires, including senior executives, have signed their employment contracts and completed their initial security training.

FREE Training Video

Implementation Guide

You are going to have to ensure that:

  • information security roles and responsibilities are documented and people are briefed on them before they get access to information
  • guidelines for information security expectations are in place and they are shared with people
  • information security policies are in place and people are aware that they are mandated
  • implement information security training and awareness relevant to people’s roles
  • have terms and conditions of employment, contracts or agreements that include information security and relate to the policies
  • information security skills and qualifications where relevant are ongoing
  • you have a whistleblowing process
  • adequate resources are made available for information security related controls and processes.

1. Implement ISO 27001 Policies

To act in accordance with ISO 27001 information security policies and procedures you first need to implement them. Follow the guidance in The Ultimate Guide to ISO 27001 Annex A 5.1 Policies for Information Security

2. Document Roles and Responsibilities

It is straight forward to document the roles and responsibilities. Start with defining what the roles are. You state the name of the role and then list what the role is responsible for in terms of information security.

Example Information Security Roles

Typical roles that are required include, but is certainly not limited to:

  • CEO
  • Leadership
  • Information Security Management Leadership
  • Information Security Manager
  • Management Review Team
  • Third Party Supplier Manager
  • Business Continuity Manager
  • Information Owners
  • Information Security Incident Management

Example Information Security Responsibilities

An example of information security responsibilities assigned to a role would be the role of the CEO. Let’s take a look:

CEO

  • Sets the company direction for information security
  • Promotes a culture of information security aligned to the business objectives
  • Signs off and agrees on resources, objectives, risks and risk treatment

3. Ensure People are Competent

Once people are assigned then we are going to record and manage their competence to perform the role. Usually this is a measure of experience and training. You are going to create and maintain an ISO 27001 Competency Matrix.

4. Engage with HR

You have a reliance on HR. There are many HR process that will come into play throughout the implementation, including on boarding new employees, off boarding when people leave, disciplinary processes and more. Specific to this particular clause you are going to have terms and conditions of employment, contracts or agreements that include information security and relate to the policies. You are going to work to ensure that information security is part of all HR process as appropriate.

5. Communicate and Train

A large part of this control is communication and training. Actually telling people what is expected of them. Having a communication plan in place that covers what you will communicate, when, to whom and how is a great way to set a structure for the year. Telling people where policies are, how to report incidents, who they can speak to about information security are some of the basics. Alongside this you will have training on a range of topics and requirements – you can learn more in The Ultimate Guide to ISO 27001 Annex A 6.3 Information Security Awareness, Education and Training

For further guidance read How to Implement ISO 27001:2022 Annex A 5.4

Implementation Checklist

1. Formalise Information Security Roles and Responsibilities

Establish clear lines of accountability by documenting security duties within job descriptions and organisational charts. This action results in a structured governance framework where every employee and manager understands their specific obligations toward data protection.

  • Define specific security roles using a RACI matrix (Responsible, Accountable, Consulted, Informed) to eliminate ambiguity in decision making.
  • Incorporate security-related performance objectives into annual staff appraisals to incentivise policy adherence.
  • Assign Identity and Access Management (IAM) oversight roles to departmental managers to ensure the principle of least privilege is maintained for their teams.

2. Provision Resources for Technical and Organisational Controls

Execute the allocation of budget, personnel, and technology required to maintain the ISMS. This result-focused step ensures that security initiatives are not delayed by resource constraints and that the organisation possesses the tools necessary to defend its information assets.

  • Allocate dedicated funding for critical technical safeguards, such as Multi-Factor Authentication (MFA) and Endpoint Detection and Response (EDR) solutions.
  • Provision time for staff to engage in mandatory security awareness training and incident response tabletop exercises.
  • Ensure the availability of Subject Matter Experts (SMEs) to guide project teams on security-by-design principles.

3. Enforce Policy Adherence Through Visible Leadership

Demonstrate management commitment by lead-by-example participation in security protocols. This action results in increased workforce engagement and validates the importance of the Acceptable Use Policy (AUP) across the entire hierarchy.

  • Require senior leadership to sign off on core security policies, documenting their approval for audit evidence.
  • Ensure managers regularly communicate security updates and threat alerts during departmental briefings.
  • Verify that leadership personnel undergo the same rigorous background screening and training requirements as junior staff to maintain internal trust.

4. Establish a Formalised Disciplinary Process for Security Violations

Coordinate with Human Resources to document a transparent process for handling security non-compliance. This action results in a credible deterrent against negligence and provides a clear “Rules of Engagement” (ROE) document for policy enforcement.

  • Define a tiered disciplinary framework that distinguishes between accidental errors and intentional policy violations.
  • Ensure the disciplinary process is communicated clearly to all employees during the onboarding phase.
  • Maintain confidential logs of disciplinary actions taken as evidence for auditors to prove the control is active and enforced.

5. Operationalise Whistleblowing and Reporting Mechanisms

Deploy secure channels that allow personnel to report risks or policy violations without fear of reprisal. This fosters a transparent security culture where management is alerted to vulnerabilities before they are exploited.

  • Implement an anonymous reporting tool or dedicated email alias for security concerns.
  • Document a non-retaliation clause within the Information Security Policy to protect whistleblowers.
  • Review reported incidents monthly to identify cultural trends or recurring policy gaps.

6. Mandate Security Competency and Awareness Baselining

Direct the implementation of a continuous training program that verifies staff competence. This ensures that management does not simply assume security knowledge but actively validates it through testing and simulation.

  • Authorise the use of phishing simulation campaigns to test real-world user resilience.
  • Review training completion rates for high-risk groups, such as Finance and DevOps teams.
  • Link training outcomes to access privileges: requiring course completion before granting access to sensitive Asset Registers.

7. Integrate Security into Change Management Workflows

Embed security oversight into the operational change process to prevent unauthorised or risky modifications. This action ensures management retains control over the technical environment and maintains system integrity.

  • Appoint security representatives to the Change Advisory Board (CAB) to review significant infrastructure changes.
  • Enforce a strict separation of duties (SoD) between development and production environments.
  • Require management approval for emergency changes or “break-glass” procedures.

8. Define External Interface and Vendor Responsibilities

Extend management responsibility to the supply chain by defining how third parties interact with organisational data. This mitigates the risk of data breaches originating from vendors or contractors.

  • Mandate security schedules and Right to Audit clauses in all supplier contracts.
  • Assign internal contract owners responsible for monitoring vendor security performance.
  • Review third-party access logs regularly to ensure adherence to the agreed Scope of Work.

9. Execute Regular Management Reviews of Security Performance

Perform structured reviews of ISMS metrics, audit findings, and incident reports. This result-oriented step allows management to identify systemic weaknesses and authorise corrective actions to ensure continuous improvement.

  • Schedule quarterly management review meetings in alignment with ISO 27001 Clause 9.3 requirements.
  • Analyse Key Performance Indicators (KPIs), such as the time taken to revoke access for leavers or training completion rates.
  • Document the minutes and action items from these reviews to provide a verifiable trail of management involvement in security governance.

10. Verify Effectiveness via Independent Internal Audit

Commission impartial audits to validate that management responsibilities are being discharged effectively. This provides the Board with objective assurance that the security governance framework is functioning as intended.

  • Approve an annual Internal Audit Programme that covers leadership and governance controls.
  • Ensure auditors have direct access to the Board or Audit Committee to report findings without interference.
  • Track the closure of Non-Conformities (NCs) raised against management controls to demonstrate continuous improvement.

ISO 27001 Roles and Responsibilities Template

The Documented Roles and Responsibilities Template has the roles already defined with the responsibilities already written.

ISO 27001 Annex A 5.2 Information Security Roles and Responsibilities Template - ISO 27001 Annex A 5.4 Template

ISO 27001 Competency Template

For competency the great ISO 27001 Competency Matrix will get you up to speed fast.

ISO 27001 Competency Matrix Template - ISO 27001 Annex A 5.4 Template

Manager’s Monthly Checklist Example

ActionWhy?Evidence
Brief TeamRemind staff of policies (e.g., locking screens).Meeting Minutes.
Check ComplianceVerify staff completed security training.Training Log.
Enforce RulesCorrect bad behavior (e.g., password sharing).Disciplinary Note / Email.
Lead by ExampleWear ID badge visible at all times.Visual Observation (Audit).

How to comply

To comply with ISO 27001 Annex A 5.4 you are going to implement the ‘how’ to the ‘what’ the control is expecting. In short measure you are going to:

Summary: For Annex A 5.4, the auditor wants to see that management is actively involved and that people are held accountable for security responsibilities. The High Table ISO 27001 Toolkit provides the governance framework to satisfy this requirement immediately. It is the most direct, cost-effective way to achieve compliance using permanent documentation that you own and control.

How to audit it

Read the following for guidance on How to Audit ISO 27001 Annex A 5.4

1. Interview Senior Management on ISMS Objectives

Conduct direct interviews with top management to assess their understanding of the ISMS. The goal is to determine if they can articulate the organisation’s security objectives without relying on a script.

  • Ask specific questions about the organisation’s top three information security risks and how they are currently being mitigated.
  • Request evidence that management communicates the importance of effective information security to all staff (e.g., town hall emails or video briefings).
  • Verify that they understand their specific accountability for the effectiveness of the ISMS.

2. Review Management Review Meeting Minutes

Examine the minutes from the most recent Management Review Meetings (MRM) to ensure security is a standing agenda item. This confirms that governance is active rather than theoretical.

  • Check for documented decisions regarding risk acceptance, budget approval, and resource allocation.
  • Verify that action items assigned to management during previous meetings have been tracked to closure.
  • Ensure the minutes reflect a review of audit results and feedback from interested parties.

3. Inspect Job Descriptions and Organisational Charts

Audit HR documentation to verify that information security responsibilities are formally defined and communicated. Ambiguity in roles is a common major non-conformity.

  • Sample a cross-section of job descriptions (including non-IT roles) to check for specific security clauses.
  • Review the organisational chart to ensure the CISO or Security Lead has a direct reporting line to top management.
  • Check signed induction checklists to confirm new hires have acknowledged their security responsibilities.

4. Validate Resource Allocation and Budgeting

Request financial or project evidence that management has provided adequate resources for the ISMS. A policy without a budget is effectively an empty promise.

  • Review purchase orders or invoices for security tools such as Multi-Factor Authentication (MFA) or Endpoint Detection and Response (EDR).
  • Check resource planning documents to ensure staff have allocated time for ISMS maintenance tasks (e.g., internal audits).
  • Confirm that budget requests for critical security remediation have been reviewed and approved.

5. Audit Security Awareness and Training Records

Examine the training matrix to verify that management enforces competency requirements across the organisation. High completion rates demonstrate management commitment.

  • Check the Learning Management System (LMS) for 100% completion rates of mandatory onboarding training.
  • Review records for targeted training provided to high-risk roles, such as developers or finance teams.
  • Look for evidence of remedial training assigned to staff who fail phishing simulations.

6. Verify the Whistleblowing and Reporting Process

Test the mechanisms available for staff to report security concerns. An effective management system must provide a safe channel for feedback.

  • Inspect the anonymous reporting tool or email workflow to ensure it is functional and monitored.
  • Review the log of reported incidents to see if they are being triaged and investigated within agreed SLAs.
  • Check the Whistleblowing Policy to ensure it explicitly protects reporters from retaliation.

7. Examine Disciplinary Process Documentation

Review the disciplinary policy to ensure there is a clear framework for handling security violations. This acts as the enforcement arm of management responsibility.

  • Check that the Acceptable Use Policy (AUP) links directly to the disciplinary procedure.
  • Interview HR to confirm that the process applies equally to all staff, including senior management.
  • Review redacted records of past disciplinary actions (if any) to verify consistent application of the policy.

8. Observe “Tone at the Top” in Daily Operations

Conduct a physical or virtual walkthrough to observe if management follows their own rules. Leadership behaviour sets the standard for the rest of the organisation.

  • Check if managers are wearing their ID badges and locking their screens when away from their desks.
  • Observe if sensitive documents are left on printers or desks in management offices (Clear Desk Policy).
  • Verify that managers do not bypass security controls, such as sharing accounts or disabling MFA.

9. Review Change Management Approvals

Audit the Change Advisory Board (CAB) records to verify management oversight on infrastructure changes. This ensures that security risks are considered before deployment.

  • Select a sample of “Emergency Changes” and verify that they received retrospective management sign-off.
  • Check that significant changes to the ISMS scope or risk profile were discussed in management meetings.
  • Ensure that segregation of duties is maintained in the approval workflow.

10. Check Follow-Up on Non-Conformities

Review the Corrective Action Log to see how management responds to issues. A healthy ISMS is defined by how it fixes problems, not just by the absence of them.

  • Verify that management allocates resources to fix root causes identified in previous audits.
  • Check that overdue non-conformities are flagged to senior leadership for escalation.
  • Ensure that the “effectiveness of action taken” is reviewed and signed off by a responsible manager.

How to pass the audit

To pass an audit of ISO 27001 Annex A 5.4 Management Responsibilities you are going to make sure that you have followed the steps above in how to comply.

Top 3 Mistakes and How to Fix Them

In my experience, the top 3 mistakes people make for ISO 27001 Annex A 5.4 Management Responsibilities are:

  1. You have no contracts in place: You need to have contracts in place and they need to include relevant information security requirements. This can often be overlooked or the contracts that you have can be out of date. It is a good idea to check before the audit.
  2. One or more members of your team haven’t done what they should have done: Prior to the audit check that all members of the team have done what they should have. Do they know where the policies are? Have they acknowledged them? Did someone join last month and forget to do it? Check!
  3. Your document and version control is wrong: Keeping your document version control up to date, making sure that version numbers match where used, having a review evidenced in the last 12 months, having documents that have no comments in are all good practices.
Industry Standard / LawRelevant Section / RequirementMapping to Management Responsibilities (A.5.4)
NIST SP 800-53 (Rev. 5)PL-4 (Rules of Behaviour) & PM-10Management must establish and sign “Rules of Behaviour.” Mirrors A.5.4’s requirement for management to mandate policy adherence.
NIS2 Directive (EU)Article 20 (Governance)Mandates that “management bodies” approve and oversee risk management. Introduces personal liability for senior leaders for non-compliance.
DORA (EU)Article 5 (Governance)Places “ultimate responsibility” on the Board for ICT risk. Management must ensure staff are trained and roles are executed as defined in the ICT strategy.
SOC2 (AICPA)CC1.3 (COSO Principle 3)Management must establish “Tone at the Top” and hold individuals accountable for their internal control responsibilities.
UK Data (Use & Access) Act 2025Governance & Accountability ReformsWhile reducing “paperwork”, it requires management to justify “Recognised Legitimate Interests” and ensure high security thresholds for automated decision-making.
UK Cyber Security & Resilience BillMSPs & Senior LiabilityExpands reporting duties for Managed Service Providers. Management must ensure personnel are “competent” (often mapped to UK Cyber Security Council titles).
CIRCIA (USA)Reporting GovernanceRequires management to ensure staff are capable of identifying and reporting “covered incidents” to CISA within 72 hours.
EU Product Liability Directive (PLD)Strict Liability for SoftwareManagement is strictly liable for cybersecurity flaws in software. Requires management oversight of the entire product lifecycle to ensure “safety-relevant” security.
ECCF (EU Certification)Harmonised Security LabelsManagement must attest to the “Self-Assessment” or “Third-Party” certification levels (Basic, Substantial, High) for products and services.
EU AI ActArticle 17 (Quality Management)Providers of High-Risk AI must implement a QMS where management is accountable for data quality, human oversight, and post-market monitoring.
ISO/IEC 42001 (AI Management)Clause 5.1 (Leadership)Direct alignment. Management must provide resources and ensure AI security objectives are integrated into business processes.
GDPR (EU/UK)Article 5(2) & 24The “Accountability Principle.” Management must demonstrate they have implemented appropriate technical and organisational measures.
HIPAA (USA)45 CFR § 164.308 (Admin Safeguards)Requires a “Security Management Process” including Sanction Policies (A.5.4’s disciplinary requirement) and assigned security responsibility.
CCPA / CPRA (California)Section 1798.100 (Governance)Requires management to assign a “team or individual” responsible for privacy and perform annual risk assessments/audits.

Applicability across different business models

Business TypeApplicability & InterpretationExamples of Control
Small Businesses

Tone from the Top. In a small team, if the owner bypasses security (e.g., sharing passwords), everyone else will too. Compliance requires management to lead by example, not just sign a policy.

The “CEO Training” Rule: Ensuring the Managing Director completes the same cybersecurity awareness training as the newest intern. • Visible Enforcement: The owner actively using the company Password Manager during team meetings to demonstrate it is mandatory.

Tech Startups

Culture over Compliance. Management responsibility isn’t just about the CISO; it’s about Engineering Leads enforcing secure coding standards. It prevents “Security” from becoming a blocker to “Shipping.”

Blocker Authority: Empowering Engineering Managers to block a release if security checks fail, proving that safety outranks speed. • Resource Allocation: Explicitly budgeting developer hours in the sprint for “Security Debt” repayment, authorized by the CTO.

AI Companies

Ethical Oversight. Management must take responsibility for the safety of the models they release. This goes beyond data security into AI alignment and preventing misuse.

Model Sign-off: A “Go/No-Go” release meeting where the Head of Research must sign off on the safety report before a model is deployed. • Whistleblowing Channels: Establishing a clear, anonymous channel for researchers to report safety concerns about model behavior directly to the Board.

Mapped to other Standards and Laws

Framework / RegulationRelevant Control or SectionMapping to Management Responsibilities (Annex A 5.4)
NIST SP 800-53 (Rev 5)PL-4 (Rules of Behavior) PM-10 (Security Authorization Process)Direct equivalence. NIST PL-4 requires management to establish and sign rules of behaviour, mirroring the A.5.4 requirement for personnel to apply security in accordance with established policy.
EU NIS 2 DirectiveArticle 20 (Governance) Article 21 (Risk Management Measures)NIS 2 Article 20 mandates that “management bodies” approve and oversee cybersecurity measures. Annex A 5.4 provides the operational evidence (staff adherence) required to satisfy this governance obligation.
EU DORAArticle 5 (Governance and Organisation)DORA explicitly places “ultimate responsibility” on the management body. Implementing A.5.4 ensures that the roles and strategies defined by the Board under Article 5 are actually executed by staff.
UK Cyber Security & Resilience BillSenior Management Liability (Pending Legislation)Expected to mirror NIS 2, this Bill introduces personal liability for senior managers. A.5.4 compliance is the primary defence mechanism, demonstrating that management actively enforced security policies rather than just documenting them.
SOC 2 (AICPA)CC1.3 (COSO Principle 3) CC5.3 (Risk Mitigation)SOC 2 requires management to establish “tone at the top”. Auditors test A.5.4 by verifying if management holds individuals accountable for internal control responsibilities.
CIRCIA (USA)Reporting Governance (CISA Reporting Requirements)Mandates 72-hour reporting for critical infrastructure. A.5.4 is essential here: management must ensure staff are trained and obligated to report incidents immediately to meet this federal deadline.
EU Product Liability Directive (PLD)Strict Liability for Software (Defectiveness)The PLD extends strict liability to software defects, including security flaws. Management responsibilities (A.5.4) now extend to ensuring developers follow “Security by Design” principles to prevent liability claims.
UK Data (Use and Access) Act 2025Accountability Principle (Amended UK GDPR)While reducing some administrative burdens (e.g., simplified ROPA), the Act maintains strict accountability. A.5.4 ensures that staff understand and apply the new “Recognised Legitimate Interests” for data processing correctly.
EU AI ActArticle 4 (AI Literacy) Article 9 (Risk Management)Management must ensure personnel are competent in using AI systems (Article 4). A.5.4 enforces the usage policies required to prevent “High-Risk” AI systems from drifting into non-compliance.
HIPAA (USA)§ 164.308(a)(1) (Security Management Process)Requires covered entities to implement policies and procedures. A.5.4 is the “Administrative Safeguard” that ensures the workforce actually complies with these HIPAA sanctions policies.
ECCFCyber Resilience Act (CRA) LinksFor EU-wide certification, management must affirm that processes are followed. A.5.4 provides the internal audit trail required to achieve “Substantial” or “High” assurance levels under the framework.

FAQ

Is a formal disciplinary process mandatory for Annex A 5.4?

Yes, management must establish, communicate, and maintain a formalised disciplinary process to handle employees who violate security policies.

What is the difference between Clause 5 and Annex A 5.4?

While Clause 5 focuses on high-level leadership and the overall ISMS strategy, Annex A 5.4 is an operational control focused on management’s role in enforcing policy adherence among staff.

How can management demonstrate commitment to ISO 27001?

Management demonstrates commitment by integrating security into business processes and ensuring that security objectives are aligned with organisational goals.

ISO 27001 Controls and Attribute Values

Control typeInformation
security properties
Cybersecurity
concepts
Operational
capabilities
Security domains
PreventiveConfidentialityIdentifyGovernanceGovernance and Ecosystem
Integrity
Availability

About the author

Stuart Barker
🎓 MSc Security 🛡️ Lead Auditor 30+ Years Exp 🏢 Ex-GE Leader

Stuart Barker

ISO 27001 Ninja

Stuart Barker is a veteran practitioner with over 30 years of experience in systems security and risk management. Holding an MSc in Software and Systems Security, he combines academic rigor with extensive operational experience, including a decade leading Data Governance for General Electric (GE).

As a qualified ISO 27001 Lead Auditor, Stuart possesses distinct insight into the specific evidence standards required by certification bodies. His toolkits represent an auditor-verified methodology designed to minimise operational friction while guaranteeing compliance.

ISO 27001 Annex A 5.4 Management responsibilities
Shopping Basket
Scroll to Top