Auditen
Home / Frameworks / ISO 27001 / Leadership and the security policy
ISO 27001 · Clause 5

Leadership and the security policy

Clause 5 requires top management to demonstrate active leadership and commitment to the Information Security Management System (ISMS). This involves establishing a high-level information security policy that provides direction, aligns with business objectives, and ensures resources are available to maintain security.

What it means

Leadership is not merely an endorsement; it is an active requirement for top management to ensure the ISMS is integrated into the organization's core business processes rather than treated as a standalone IT project. Management must take accountability for the effectiveness of the system and promote a culture of security across all levels.

The "Security Policy" mentioned here is a high-level governing document. It is not a technical manual or a set of detailed procedures, but a statement of intent. It defines the organization's overall approach to risk, its commitment to meeting legal/regulatory requirements, and its goal for continuous improvement.

How to meet it

Evidence an auditor asks for

  • A signed, dated Information Security Policy that is current and available to staff.
  • Records of communication (e.g., email broadcasts or training logs) proving employees have read/acknowledged the policy.
  • Minutes from management meetings showing discussions on security risks, resource allocation, and ISMS performance.
  • Job descriptions or an organizational chart identifying who is responsible for information security.
  • Evidence of budget approval or resource procurement specifically tied to security requirements.

Common pitfalls

  • The "Rubber Stamp" approach: Top management signs the policy but cannot explain its contents or goals during an audit interview.
  • Over-detailing the policy: Including specific technical settings (e.g., password lengths) in the high-level policy, which makes it obsolete every time a tool changes.
  • Lack of communication: Having a perfect policy document that is stored on a server where no regular employee can find or read it.
  • Treating security as "an IT problem": Failing to show evidence that business leadership—not just the IT Manager—is driving the ISMS.