ISO 27001A.5 — Management responsibilities
A.5.4
Management responsibilities
ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026
Objective
Ensure management requires personnel to apply information security in accordance with established policies and procedures.
Points of focus
- Managers accountable for team security behaviours
- Security expectations included in role goals
- Escalation when policy is ignored
- Visible sponsorship of ISMS activities
Implementation notes
Make managers first-line owners of joiner access, exception requests, and secure delivery expectations. Put security behaviours in role descriptions and onboarding checklists. Route production access and data-export exceptions through the manager of record. During management review, ask leaders to confirm resource support for remediation — Stage 2 often probes whether management actually directs the ISMS.
Audit tip: Interview one engineering manager about how they enforce MFA and change rules — answers should match policy.
Evidence auditors typically request:
- Manager acknowledgement of security responsibilities
- Performance or OKR language referencing secure practices
- Access-approval samples signed by managers
- Management review attendance records
Common gaps
- Security treated as 'the compliance person's job' only
- Managers approve access without reading risk context
- No consequence path when teams bypass change control
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.5.4 | This control |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.5.4)
Frequently Asked Questions
No. It requires management responsibility. Small SaaS teams can assign an ISMS owner with executive sponsor; clarity beats title inflation.
A.5.2 defines roles; A.5.4 expects managers to make people follow the rules those roles define.
Documented approvals, training completion owned by managers, and meeting notes where leaders close security actions.