Leadership and the security policy
Clause 5 requires top management to demonstrate active leadership and commitment to the Information Security Management System (ISMS). This involves establishing a high-level information security policy that provides direction, aligns with business objectives, and ensures resources are available to maintain security.
What it means
Leadership is not merely an endorsement; it is an active requirement for top management to ensure the ISMS is integrated into the organization's core business processes rather than treated as a standalone IT project. Management must take accountability for the effectiveness of the system and promote a culture of security across all levels.
The "Security Policy" mentioned here is a high-level governing document. It is not a technical manual or a set of detailed procedures, but a statement of intent. It defines the organization's overall approach to risk, its commitment to meeting legal/regulatory requirements, and its goal for continuous improvement.
How to meet it
- Draft a high-level Information Security Policy that outlines the organization's security objectives and commitment to the ISMS.
- Ensure top management formally reviews and approves the policy (e.g., via digital signature or board meeting minutes).
- Communicate the policy to all employees and relevant external parties through accessible channels like an intranet, employee handbook, or email.
- Allocate necessary resources—including budget, personnel, and tools—to implement and maintain security controls.
- Assign specific roles and responsibilities for information security and ensure these are documented and understood by those holding them.
- Establish a regular cadence for management reviews to evaluate the performance of the ISMS and make strategic adjustments.
Evidence an auditor asks for
- A signed, dated Information Security Policy that is current and available to staff.
- Records of communication (e.g., email broadcasts or training logs) proving employees have read/acknowledged the policy.
- Minutes from management meetings showing discussions on security risks, resource allocation, and ISMS performance.
- Job descriptions or an organizational chart identifying who is responsible for information security.
- Evidence of budget approval or resource procurement specifically tied to security requirements.
Common pitfalls
- The "Rubber Stamp" approach: Top management signs the policy but cannot explain its contents or goals during an audit interview.
- Over-detailing the policy: Including specific technical settings (e.g., password lengths) in the high-level policy, which makes it obsolete every time a tool changes.
- Lack of communication: Having a perfect policy document that is stored on a server where no regular employee can find or read it.
- Treating security as "an IT problem": Failing to show evidence that business leadership—not just the IT Manager—is driving the ISMS.