Management Responsibilities - ISO 27001 Annex A Control

ISO 27001 Annex A 5.4

Management have to support the security arrangements they are asking staff to follow.

ISO 27001 Annex A 5.4 - Management Responsibilities

This control is about active management. It expects managers to do more than agree the policies exist. They have to require their teams to apply them, set the example themselves, and treat information security as part of normal supervision rather than an HR or IT problem someone else handles.

In practice this comes through in induction, in awareness training, in line management conversations, in the way breaches are dealt with, and in the way managers handle information security questions when staff raise them. If managers ignore the policies or treat them as optional, the policies have no real authority.

The control sits next to Annex A 6.3 on awareness and training. The two work together. Awareness training tells staff what the rules are and why. Management responsibility means the rules are enforced and reinforced day to day. Both need to be in place.

Management responsibility is one of those things that sounds obvious but often is not delivered. The auditor walks in, and you can usually tell within the first hour whether managers actually care about information security or whether they tick the box and move on. If they care, the staff know what the policies are and why, and it shows in how they answer questions.

Practical Compliance Guidance

The expectation that managers actively reinforce information security is set out in the IMS1 Manual Section 8.1 on commitment to information security management, and Section 3.1 Management of Staff and Company Personnel. All workers are made aware of company policies during induction and annual review.

alphaZ document How to use it
ISO 27001 Toolkit The full alphaZ ISO 27001 toolkit, including the IMS1 Manual, information security risks register, policy-procedures, forms, registers and audit checklists. 
P35 Information Security Awareness Policy Sets out the awareness expectations for staff at all levels, including the role of managers in reinforcing the policies and following up on issues.

Note - all the above files can be downloaded with an alphaZ subscription.

Frequently Asked Questions

Auditors will speak to staff at different levels and ask about information security in their day-to-day work. They will look for consistency between what the policies say, what management says and what staff actually do. Induction records, training completion logs, line management discussions and how breaches have been handled all form part of the evidence.
Not formally, but managers need to understand the policies they are enforcing. In practice most organisations include managers in the same awareness training as other staff, plus additional briefing on their reinforcement role. The audit will look for evidence that managers know enough to handle information security questions and issues sensibly.
Annex A 5.2 is about defining and allocating the named roles. Annex A 5.4 is about the active reinforcement role of management once those responsibilities are allocated. Together they cover both the structure and the behaviour.

Further Resources

payment logos