ISO27001:2022 – A5.4 Management responsibilities
Introduction to ISO 27001 – A5.4
In the previous control, A5.3 Segregation of Duties, we outlined our expectations of key personnel and teams. ISO 27001 – A5.4 has a slightly different focus and emphasis, which if missed, could be problematic.
What does ISO 27001 – A5.4 require?
The standard states that:
“Management shall require all personnel to apply information security in accordance with the established Information security policy, topic-specific policies and procedures of the organisation.” (A5.4 Management Responsibilities)
This focuses on three distinct areas:
- The high-level information security policy
- Topic-specific policies (e.g. Data Protection, Remote working)
- Procedures (e.g. Patch Management, Business Continuity)
Why is this required?
The purpose of this control is to ensure management understands their role in information security and undertakes actions that ensure all personnel are aware of and fulfil their responsibilities.
This control emphasises the critical role management plays in developing and supporting a culture that respects and understands information security. Leadership is key to ISO27001. Without visible, ongoing support for information security, the entire programme may fail or be very difficult to manage.
What the auditor is looking for
The auditor may check several sources for evidence of compliance with this control, including:
- Security policies and procedures:
Reviewing when they were developed, signed off, and communicated shows how seriously the topic is taken. - Employment and contractor contracts:
These should specify that compliance with company policies is mandatory. - Availability of information security documentation:
Policies and procedures should be easily accessible and well-organised. - Internal communication and training:
Evidence of security-focused communications like emails, newsletters, or briefings reinforces management commitment. - Employee training records:
These show that personnel have been trained on information security expectations and responsibilities.
Q & A
How often should policies be reviewed and re-communicated?
Policies should be reviewed and updated at least every 12 months. Any major organisational or infrastructure changes (e.g. mergers or restructures) should trigger a documentation review.
How can management ensure interested parties are aware of their obligations?
For staff, check training records, one-to-one meetings, and internal reviews. For suppliers and partners, review contractual terms regularly to ensure policy compliance is clear.
What happens if someone breaks a policy?
All policies should include a clear statement about consequences for non-compliance — e.g., “A breach of our policies may be treated as a disciplinary matter and handled accordingly.”
Difficulty rating
We rate this a 2 out of 5. This control requires minimal technical skill but a consistent management approach.
More questions?
Nothing in ISO27001 stands alone. Review our FAQ for more insights into related controls.
We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book “The Real Easy Guide to ISO27001”, available on Amazon.
