Skip to content
compliancebase
ISO 27001A.5 — Management responsibilities

A.5.4

Management responsibilities

ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026

Objective

Ensure management requires personnel to apply information security in accordance with established policies and procedures.

Points of focus

  • Managers accountable for team security behaviours
  • Security expectations included in role goals
  • Escalation when policy is ignored
  • Visible sponsorship of ISMS activities

Implementation notes

Make managers first-line owners of joiner access, exception requests, and secure delivery expectations. Put security behaviours in role descriptions and onboarding checklists. Route production access and data-export exceptions through the manager of record. During management review, ask leaders to confirm resource support for remediation — Stage 2 often probes whether management actually directs the ISMS.

Audit tip: Interview one engineering manager about how they enforce MFA and change rules — answers should match policy.

Evidence auditors typically request:

  • Manager acknowledgement of security responsibilities
  • Performance or OKR language referencing secure practices
  • Access-approval samples signed by managers
  • Management review attendance records

Common gaps

  • Security treated as 'the compliance person's job' only
  • Managers approve access without reading risk context
  • No consequence path when teams bypass change control

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.5.4This control

Primary sources

Frequently Asked Questions

No. It requires management responsibility. Small SaaS teams can assign an ISMS owner with executive sponsor; clarity beats title inflation.

A.5.2 defines roles; A.5.4 expects managers to make people follow the rules those roles define.

Documented approvals, training completion owned by managers, and meeting notes where leaders close security actions.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: July 2026 · Primary sources linked above