ISO 27001A.5 — Management responsibilities
A.5.4
Management responsibilities
ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026
Objective
Ensure management requires personnel to apply information security in accordance with established policies and procedures.
Points of focus
- Managers accountable for team security behaviours
- Security expectations included in role goals
- Escalation when policy is ignored
- Visible sponsorship of ISMS activities
Implementation notes
Make managers first-line owners of joiner access, exception requests, and secure delivery expectations. Put security behaviours in role descriptions and onboarding checklists. Route production access and data-export exceptions through the manager of record. During management review, ask leaders to confirm resource support for remediation — Stage 2 often probes whether management actually directs the ISMS.
Audit tip: Interview one engineering manager about how they enforce MFA and change rules — answers should match policy.
Evidence auditors typically request:
- Manager acknowledgement of security responsibilities
- Performance or OKR language referencing secure practices
- Access-approval samples signed by managers
- Management review attendance records
Common gaps
- Security treated as 'the compliance person's job' only
- Managers approve access without reading risk context
- No consequence path when teams bypass change control
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.5.4 | This control |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.5.4)
Frequently Asked Questions
No. It requires management responsibility. Small SaaS teams can assign an ISMS owner with executive sponsor; clarity beats title inflation.
A.5.2 defines roles; A.5.4 expects managers to make people follow the rules those roles define.
Documented approvals, training completion owned by managers, and meeting notes where leaders close security actions.
Auditors typically request manager acknowledgement of security responsibilities and walkthrough how management responsibilities operates in practice — prepare dated samples, not policy PDFs alone.