ISO 27001 Management Responsibilities
ISO 27001 Management Responsibilities is an ISO 27001 control that requires management to ensure that people apply information security in line with documented policies and procedures.
It is ensuring that information security is led from the top down.
Table of contents
- ISO 27001 Management Responsibilities
- Key Takeaways
- Purpose
- Definition
- Explanation
- Requirement
- Audit Focus
- FREE Training Video
- Implementation Guide
- Implementation Checklist
- ISO 27001 Roles and Responsibilities Template
- ISO 27001 Competency Template
- Manager’s Monthly Checklist Example
- How to comply
- How to audit it
- How to pass the audit
- Top 3 Mistakes and How to Fix Them
- Applicable Laws and Related Standards
- Applicability across different business models
- Mapped to other Standards and Laws
- FAQ
- ISO 27001 Controls and Attribute Values
Key Takeaways
ISO 27001 Annex A 5.4 requires senior management to actively ensure that all personnel follow the organization’s information security policies and procedures. This control shifts security from being “the IT department’s problem” to a top-down leadership mandate. The goal is to ensure that management understands their role in fostering a security culture and provides the necessary resources, oversight, and legal frameworks to enforce data protection standards across the entire workforce.
- Leaders are responsible for making sure everyone follows the security rules.
- Companies need to train their staff so they know their part in keeping information safe.
- Clear security policies and job duties should be written down for all to see.
Purpose
The purpose of Annex A 5.4 is to ensure management understand their role in information security and undertake actions aiming to ensure all personnel are aware of and fulfil their information security responsibilities.
Definition
The ISO 27001 standard defines ISO 27001 Management Responsibilities as:
Management should require all personnel to apply information security in accordance with the established information security policy, topic-specific policies and procedures of the organization.
ISO 27001 Annex A 5.4 Management Responsibilities
Explanation
ISO 27001 Annex A 5.4 Management Responsibilities is a security control that requires senior leadership to mandate information security policy adherence. The primary implementation requirement is a top-down governance framework where management provides resources and enforces accountability, delivering the business benefit of a robust, leadership-driven security culture across the workforce.
Requirement
- Mandated Compliance: Management must require all staff and contractors to apply information security in accordance with established policies. This isn’t optional; it must be a condition of employment.
- Resource Allocation: Leaders must provide adequate resources (budget, time, and tools) to implement and maintain the Information Security Management System (ISMS).
- Competence & Skills: Management is responsible for ensuring that personnel are competent for their security roles. This involves maintaining a Competency Matrix to track training, experience, and certifications.
- Contractual Enforcement: Security requirements must be explicitly stated in employment contracts and third-party agreements to ensure they are legally enforceable.
- Whistleblowing Process: Management must implement a process that allows employees to report security concerns or violations anonymously and without fear of retaliation.
Audit Focus
- Direct Evidence: “Show me the meeting minutes where senior management reviewed the risk register and approved the security budget.”
- The Whistleblower Test: “If an employee sees a manager bypassing security rules, how do they report it? Show me the documented process.”
- Policy Acknowledgement: They will check if all new hires, including senior executives, have signed their employment contracts and completed their initial security training.
FREE Training Video
Implementation Guide
You are going to have to ensure that:
- information security roles and responsibilities are documented and people are briefed on them before they get access to information
- guidelines for information security expectations are in place and they are shared with people
- information security policies are in place and people are aware that they are mandated
- implement information security training and awareness relevant to people’s roles
- have terms and conditions of employment, contracts or agreements that include information security and relate to the policies
- information security skills and qualifications where relevant are ongoing
- you have a whistleblowing process
- adequate resources are made available for information security related controls and processes.
1. Implement ISO 27001 Policies
To act in accordance with ISO 27001 information security policies and procedures you first need to implement them. Follow the guidance in The Ultimate Guide to ISO 27001 Annex A 5.1 Policies for Information Security
2. Document Roles and Responsibilities
It is straight forward to document the roles and responsibilities. Start with defining what the roles are. You state the name of the role and then list what the role is responsible for in terms of information security.
Example Information Security Roles
Typical roles that are required include, but is certainly not limited to:
- CEO
- Leadership
- Information Security Management Leadership
- Information Security Manager
- Management Review Team
- Third Party Supplier Manager
- Business Continuity Manager
- Information Owners
- Information Security Incident Management
Example Information Security Responsibilities
An example of information security responsibilities assigned to a role would be the role of the CEO. Let’s take a look:
CEO
- Sets the company direction for information security
- Promotes a culture of information security aligned to the business objectives
- Signs off and agrees on resources, objectives, risks and risk treatment
3. Ensure People are Competent
Once people are assigned then we are going to record and manage their competence to perform the role. Usually this is a measure of experience and training. You are going to create and maintain an ISO 27001 Competency Matrix.
4. Engage with HR
You have a reliance on HR. There are many HR process that will come into play throughout the implementation, including on boarding new employees, off boarding when people leave, disciplinary processes and more. Specific to this particular clause you are going to have terms and conditions of employment, contracts or agreements that include information security and relate to the policies. You are going to work to ensure that information security is part of all HR process as appropriate.
5. Communicate and Train
A large part of this control is communication and training. Actually telling people what is expected of them. Having a communication plan in place that covers what you will communicate, when, to whom and how is a great way to set a structure for the year. Telling people where policies are, how to report incidents, who they can speak to about information security are some of the basics. Alongside this you will have training on a range of topics and requirements – you can learn more in The Ultimate Guide to ISO 27001 Annex A 6.3 Information Security Awareness, Education and Training
For further guidance read How to Implement ISO 27001:2022 Annex A 5.4
Implementation Checklist
1. Formalise Information Security Roles and Responsibilities
Establish clear lines of accountability by documenting security duties within job descriptions and organisational charts. This action results in a structured governance framework where every employee and manager understands their specific obligations toward data protection.
- Define specific security roles using a RACI matrix (Responsible, Accountable, Consulted, Informed) to eliminate ambiguity in decision making.
- Incorporate security-related performance objectives into annual staff appraisals to incentivise policy adherence.
- Assign Identity and Access Management (IAM) oversight roles to departmental managers to ensure the principle of least privilege is maintained for their teams.
2. Provision Resources for Technical and Organisational Controls
Execute the allocation of budget, personnel, and technology required to maintain the ISMS. This result-focused step ensures that security initiatives are not delayed by resource constraints and that the organisation possesses the tools necessary to defend its information assets.
- Allocate dedicated funding for critical technical safeguards, such as Multi-Factor Authentication (MFA) and Endpoint Detection and Response (EDR) solutions.
- Provision time for staff to engage in mandatory security awareness training and incident response tabletop exercises.
- Ensure the availability of Subject Matter Experts (SMEs) to guide project teams on security-by-design principles.
3. Enforce Policy Adherence Through Visible Leadership
Demonstrate management commitment by lead-by-example participation in security protocols. This action results in increased workforce engagement and validates the importance of the Acceptable Use Policy (AUP) across the entire hierarchy.
- Require senior leadership to sign off on core security policies, documenting their approval for audit evidence.
- Ensure managers regularly communicate security updates and threat alerts during departmental briefings.
- Verify that leadership personnel undergo the same rigorous background screening and training requirements as junior staff to maintain internal trust.
4. Establish a Formalised Disciplinary Process for Security Violations
Coordinate with Human Resources to document a transparent process for handling security non-compliance. This action results in a credible deterrent against negligence and provides a clear “Rules of Engagement” (ROE) document for policy enforcement.
- Define a tiered disciplinary framework that distinguishes between accidental errors and intentional policy violations.
- Ensure the disciplinary process is communicated clearly to all employees during the onboarding phase.
- Maintain confidential logs of disciplinary actions taken as evidence for auditors to prove the control is active and enforced.
5. Operationalise Whistleblowing and Reporting Mechanisms
Deploy secure channels that allow personnel to report risks or policy violations without fear of reprisal. This fosters a transparent security culture where management is alerted to vulnerabilities before they are exploited.
- Implement an anonymous reporting tool or dedicated email alias for security concerns.
- Document a non-retaliation clause within the Information Security Policy to protect whistleblowers.
- Review reported incidents monthly to identify cultural trends or recurring policy gaps.
6. Mandate Security Competency and Awareness Baselining
Direct the implementation of a continuous training program that verifies staff competence. This ensures that management does not simply assume security knowledge but actively validates it through testing and simulation.
- Authorise the use of phishing simulation campaigns to test real-world user resilience.
- Review training completion rates for high-risk groups, such as Finance and DevOps teams.
- Link training outcomes to access privileges: requiring course completion before granting access to sensitive Asset Registers.
7. Integrate Security into Change Management Workflows
Embed security oversight into the operational change process to prevent unauthorised or risky modifications. This action ensures management retains control over the technical environment and maintains system integrity.
- Appoint security representatives to the Change Advisory Board (CAB) to review significant infrastructure changes.
- Enforce a strict separation of duties (SoD) between development and production environments.
- Require management approval for emergency changes or “break-glass” procedures.
8. Define External Interface and Vendor Responsibilities
Extend management responsibility to the supply chain by defining how third parties interact with organisational data. This mitigates the risk of data breaches originating from vendors or contractors.
- Mandate security schedules and Right to Audit clauses in all supplier contracts.
- Assign internal contract owners responsible for monitoring vendor security performance.
- Review third-party access logs regularly to ensure adherence to the agreed Scope of Work.
9. Execute Regular Management Reviews of Security Performance
Perform structured reviews of ISMS metrics, audit findings, and incident reports. This result-oriented step allows management to identify systemic weaknesses and authorise corrective actions to ensure continuous improvement.
- Schedule quarterly management review meetings in alignment with ISO 27001 Clause 9.3 requirements.
- Analyse Key Performance Indicators (KPIs), such as the time taken to revoke access for leavers or training completion rates.
- Document the minutes and action items from these reviews to provide a verifiable trail of management involvement in security governance.
10. Verify Effectiveness via Independent Internal Audit
Commission impartial audits to validate that management responsibilities are being discharged effectively. This provides the Board with objective assurance that the security governance framework is functioning as intended.
- Approve an annual Internal Audit Programme that covers leadership and governance controls.
- Ensure auditors have direct access to the Board or Audit Committee to report findings without interference.
- Track the closure of Non-Conformities (NCs) raised against management controls to demonstrate continuous improvement.
ISO 27001 Roles and Responsibilities Template
The Documented Roles and Responsibilities Template has the roles already defined with the responsibilities already written.

ISO 27001 Competency Template
For competency the great ISO 27001 Competency Matrix will get you up to speed fast.

Manager’s Monthly Checklist Example
| Action | Why? | Evidence |
| Brief Team | Remind staff of policies (e.g., locking screens). | Meeting Minutes. |
| Check Compliance | Verify staff completed security training. | Training Log. |
| Enforce Rules | Correct bad behavior (e.g., password sharing). | Disciplinary Note / Email. |
| Lead by Example | Wear ID badge visible at all times. | Visual Observation (Audit). |
How to comply
To comply with ISO 27001 Annex A 5.4 you are going to implement the ‘how’ to the ‘what’ the control is expecting. In short measure you are going to:
- Document your information security roles and responsibilities
- Implement a program of Information Security Training and Awareness and maintain a Communication Plan
- Implement Information Security Management Policies
- Engage a HR specialist to ensure your HR documentation is legal and meets HR best practice
- Ensure you have contracts in place with all staff, contractors and third parties
- Maintain a competency matrix to track the skills and qualifications of staff
- Implement a whistleblowing process
- Free people’s time to work on information security or bring in specialist help
Summary: For Annex A 5.4, the auditor wants to see that management is actively involved and that people are held accountable for security responsibilities. The High Table ISO 27001 Toolkit provides the governance framework to satisfy this requirement immediately. It is the most direct, cost-effective way to achieve compliance using permanent documentation that you own and control.
How to audit it
Read the following for guidance on How to Audit ISO 27001 Annex A 5.4
1. Interview Senior Management on ISMS Objectives
Conduct direct interviews with top management to assess their understanding of the ISMS. The goal is to determine if they can articulate the organisation’s security objectives without relying on a script.
- Ask specific questions about the organisation’s top three information security risks and how they are currently being mitigated.
- Request evidence that management communicates the importance of effective information security to all staff (e.g., town hall emails or video briefings).
- Verify that they understand their specific accountability for the effectiveness of the ISMS.
2. Review Management Review Meeting Minutes
Examine the minutes from the most recent Management Review Meetings (MRM) to ensure security is a standing agenda item. This confirms that governance is active rather than theoretical.
- Check for documented decisions regarding risk acceptance, budget approval, and resource allocation.
- Verify that action items assigned to management during previous meetings have been tracked to closure.
- Ensure the minutes reflect a review of audit results and feedback from interested parties.
3. Inspect Job Descriptions and Organisational Charts
Audit HR documentation to verify that information security responsibilities are formally defined and communicated. Ambiguity in roles is a common major non-conformity.
- Sample a cross-section of job descriptions (including non-IT roles) to check for specific security clauses.
- Review the organisational chart to ensure the CISO or Security Lead has a direct reporting line to top management.
- Check signed induction checklists to confirm new hires have acknowledged their security responsibilities.
4. Validate Resource Allocation and Budgeting
Request financial or project evidence that management has provided adequate resources for the ISMS. A policy without a budget is effectively an empty promise.
- Review purchase orders or invoices for security tools such as Multi-Factor Authentication (MFA) or Endpoint Detection and Response (EDR).
- Check resource planning documents to ensure staff have allocated time for ISMS maintenance tasks (e.g., internal audits).
- Confirm that budget requests for critical security remediation have been reviewed and approved.
5. Audit Security Awareness and Training Records
Examine the training matrix to verify that management enforces competency requirements across the organisation. High completion rates demonstrate management commitment.
- Check the Learning Management System (LMS) for 100% completion rates of mandatory onboarding training.
- Review records for targeted training provided to high-risk roles, such as developers or finance teams.
- Look for evidence of remedial training assigned to staff who fail phishing simulations.
6. Verify the Whistleblowing and Reporting Process
Test the mechanisms available for staff to report security concerns. An effective management system must provide a safe channel for feedback.
- Inspect the anonymous reporting tool or email workflow to ensure it is functional and monitored.
- Review the log of reported incidents to see if they are being triaged and investigated within agreed SLAs.
- Check the Whistleblowing Policy to ensure it explicitly protects reporters from retaliation.
7. Examine Disciplinary Process Documentation
Review the disciplinary policy to ensure there is a clear framework for handling security violations. This acts as the enforcement arm of management responsibility.
- Check that the Acceptable Use Policy (AUP) links directly to the disciplinary procedure.
- Interview HR to confirm that the process applies equally to all staff, including senior management.
- Review redacted records of past disciplinary actions (if any) to verify consistent application of the policy.
8. Observe “Tone at the Top” in Daily Operations
Conduct a physical or virtual walkthrough to observe if management follows their own rules. Leadership behaviour sets the standard for the rest of the organisation.
- Check if managers are wearing their ID badges and locking their screens when away from their desks.
- Observe if sensitive documents are left on printers or desks in management offices (Clear Desk Policy).
- Verify that managers do not bypass security controls, such as sharing accounts or disabling MFA.
9. Review Change Management Approvals
Audit the Change Advisory Board (CAB) records to verify management oversight on infrastructure changes. This ensures that security risks are considered before deployment.
- Select a sample of “Emergency Changes” and verify that they received retrospective management sign-off.
- Check that significant changes to the ISMS scope or risk profile were discussed in management meetings.
- Ensure that segregation of duties is maintained in the approval workflow.
10. Check Follow-Up on Non-Conformities
Review the Corrective Action Log to see how management responds to issues. A healthy ISMS is defined by how it fixes problems, not just by the absence of them.
- Verify that management allocates resources to fix root causes identified in previous audits.
- Check that overdue non-conformities are flagged to senior leadership for escalation.
- Ensure that the “effectiveness of action taken” is reviewed and signed off by a responsible manager.
How to pass the audit
To pass an audit of ISO 27001 Annex A 5.4 Management Responsibilities you are going to make sure that you have followed the steps above in how to comply.
Top 3 Mistakes and How to Fix Them
In my experience, the top 3 mistakes people make for ISO 27001 Annex A 5.4 Management Responsibilities are:
- You have no contracts in place: You need to have contracts in place and they need to include relevant information security requirements. This can often be overlooked or the contracts that you have can be out of date. It is a good idea to check before the audit.
- One or more members of your team haven’t done what they should have done: Prior to the audit check that all members of the team have done what they should have. Do they know where the policies are? Have they acknowledged them? Did someone join last month and forget to do it? Check!
- Your document and version control is wrong: Keeping your document version control up to date, making sure that version numbers match where used, having a review evidenced in the last 12 months, having documents that have no comments in are all good practices.
Applicable Laws and Related Standards
| Industry Standard / Law | Relevant Section / Requirement | Mapping to Management Responsibilities (A.5.4) |
|---|---|---|
| NIST SP 800-53 (Rev. 5) | PL-4 (Rules of Behaviour) & PM-10 | Management must establish and sign “Rules of Behaviour.” Mirrors A.5.4’s requirement for management to mandate policy adherence. |
| NIS2 Directive (EU) | Article 20 (Governance) | Mandates that “management bodies” approve and oversee risk management. Introduces personal liability for senior leaders for non-compliance. |
| DORA (EU) | Article 5 (Governance) | Places “ultimate responsibility” on the Board for ICT risk. Management must ensure staff are trained and roles are executed as defined in the ICT strategy. |
| SOC2 (AICPA) | CC1.3 (COSO Principle 3) | Management must establish “Tone at the Top” and hold individuals accountable for their internal control responsibilities. |
| UK Data (Use & Access) Act 2025 | Governance & Accountability Reforms | While reducing “paperwork”, it requires management to justify “Recognised Legitimate Interests” and ensure high security thresholds for automated decision-making. |
| UK Cyber Security & Resilience Bill | MSPs & Senior Liability | Expands reporting duties for Managed Service Providers. Management must ensure personnel are “competent” (often mapped to UK Cyber Security Council titles). |
| CIRCIA (USA) | Reporting Governance | Requires management to ensure staff are capable of identifying and reporting “covered incidents” to CISA within 72 hours. |
| EU Product Liability Directive (PLD) | Strict Liability for Software | Management is strictly liable for cybersecurity flaws in software. Requires management oversight of the entire product lifecycle to ensure “safety-relevant” security. |
| ECCF (EU Certification) | Harmonised Security Labels | Management must attest to the “Self-Assessment” or “Third-Party” certification levels (Basic, Substantial, High) for products and services. |
| EU AI Act | Article 17 (Quality Management) | Providers of High-Risk AI must implement a QMS where management is accountable for data quality, human oversight, and post-market monitoring. |
| ISO/IEC 42001 (AI Management) | Clause 5.1 (Leadership) | Direct alignment. Management must provide resources and ensure AI security objectives are integrated into business processes. |
| GDPR (EU/UK) | Article 5(2) & 24 | The “Accountability Principle.” Management must demonstrate they have implemented appropriate technical and organisational measures. |
| HIPAA (USA) | 45 CFR § 164.308 (Admin Safeguards) | Requires a “Security Management Process” including Sanction Policies (A.5.4’s disciplinary requirement) and assigned security responsibility. |
| CCPA / CPRA (California) | Section 1798.100 (Governance) | Requires management to assign a “team or individual” responsible for privacy and perform annual risk assessments/audits. |
Applicability across different business models
| Business Type | Applicability & Interpretation | Examples of Control |
|---|---|---|
| Small Businesses |
Tone from the Top. In a small team, if the owner bypasses security (e.g., sharing passwords), everyone else will too. Compliance requires management to lead by example, not just sign a policy. |
• The “CEO Training” Rule: Ensuring the Managing Director completes the same cybersecurity awareness training as the newest intern. • Visible Enforcement: The owner actively using the company Password Manager during team meetings to demonstrate it is mandatory. |
| Tech Startups |
Culture over Compliance. Management responsibility isn’t just about the CISO; it’s about Engineering Leads enforcing secure coding standards. It prevents “Security” from becoming a blocker to “Shipping.” |
• Blocker Authority: Empowering Engineering Managers to block a release if security checks fail, proving that safety outranks speed. • Resource Allocation: Explicitly budgeting developer hours in the sprint for “Security Debt” repayment, authorized by the CTO. |
| AI Companies |
Ethical Oversight. Management must take responsibility for the safety of the models they release. This goes beyond data security into AI alignment and preventing misuse. |
• Model Sign-off: A “Go/No-Go” release meeting where the Head of Research must sign off on the safety report before a model is deployed. • Whistleblowing Channels: Establishing a clear, anonymous channel for researchers to report safety concerns about model behavior directly to the Board. |
Mapped to other Standards and Laws
| Framework / Regulation | Relevant Control or Section | Mapping to Management Responsibilities (Annex A 5.4) |
|---|---|---|
| NIST SP 800-53 (Rev 5) | PL-4 (Rules of Behavior) PM-10 (Security Authorization Process) | Direct equivalence. NIST PL-4 requires management to establish and sign rules of behaviour, mirroring the A.5.4 requirement for personnel to apply security in accordance with established policy. |
| EU NIS 2 Directive | Article 20 (Governance) Article 21 (Risk Management Measures) | NIS 2 Article 20 mandates that “management bodies” approve and oversee cybersecurity measures. Annex A 5.4 provides the operational evidence (staff adherence) required to satisfy this governance obligation. |
| EU DORA | Article 5 (Governance and Organisation) | DORA explicitly places “ultimate responsibility” on the management body. Implementing A.5.4 ensures that the roles and strategies defined by the Board under Article 5 are actually executed by staff. |
| UK Cyber Security & Resilience Bill | Senior Management Liability (Pending Legislation) | Expected to mirror NIS 2, this Bill introduces personal liability for senior managers. A.5.4 compliance is the primary defence mechanism, demonstrating that management actively enforced security policies rather than just documenting them. |
| SOC 2 (AICPA) | CC1.3 (COSO Principle 3) CC5.3 (Risk Mitigation) | SOC 2 requires management to establish “tone at the top”. Auditors test A.5.4 by verifying if management holds individuals accountable for internal control responsibilities. |
| CIRCIA (USA) | Reporting Governance (CISA Reporting Requirements) | Mandates 72-hour reporting for critical infrastructure. A.5.4 is essential here: management must ensure staff are trained and obligated to report incidents immediately to meet this federal deadline. |
| EU Product Liability Directive (PLD) | Strict Liability for Software (Defectiveness) | The PLD extends strict liability to software defects, including security flaws. Management responsibilities (A.5.4) now extend to ensuring developers follow “Security by Design” principles to prevent liability claims. |
| UK Data (Use and Access) Act 2025 | Accountability Principle (Amended UK GDPR) | While reducing some administrative burdens (e.g., simplified ROPA), the Act maintains strict accountability. A.5.4 ensures that staff understand and apply the new “Recognised Legitimate Interests” for data processing correctly. |
| EU AI Act | Article 4 (AI Literacy) Article 9 (Risk Management) | Management must ensure personnel are competent in using AI systems (Article 4). A.5.4 enforces the usage policies required to prevent “High-Risk” AI systems from drifting into non-compliance. |
| HIPAA (USA) | § 164.308(a)(1) (Security Management Process) | Requires covered entities to implement policies and procedures. A.5.4 is the “Administrative Safeguard” that ensures the workforce actually complies with these HIPAA sanctions policies. |
| ECCF | Cyber Resilience Act (CRA) Links | For EU-wide certification, management must affirm that processes are followed. A.5.4 provides the internal audit trail required to achieve “Substantial” or “High” assurance levels under the framework. |
FAQ
Yes, management must establish, communicate, and maintain a formalised disciplinary process to handle employees who violate security policies.
While Clause 5 focuses on high-level leadership and the overall ISMS strategy, Annex A 5.4 is an operational control focused on management’s role in enforcing policy adherence among staff.
Management demonstrates commitment by integrating security into business processes and ensuring that security objectives are aligned with organisational goals.
ISO 27001 Controls and Attribute Values
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|---|---|---|---|---|
| Preventive | Confidentiality | Identify | Governance | Governance and Ecosystem |
| Integrity | ||||
| Availability |
About the author

