Clause 5.2 requires top management to establish an information security policy. This is the top-level policy for the whole ISMS — distinct from, and sitting above, the more detailed topic-specific policies referenced in Annex A (such as access control, cryptography, or supplier relationships policies). The clause specifies that the policy must:
- Be appropriate to the purpose of the organization — a policy copied from a template with no reference to what the organization actually does will not withstand scrutiny.
- Include information security objectives, or provide the framework for setting them — the policy either states measurable objectives directly or explains how they will be set (linking forward to clause 6.2).
- Include a commitment to satisfy applicable requirements related to information security — legal, regulatory, contractual and other requirements identified under clause 4.2.
- Include a commitment to continual improvement of the ISMS.
Beyond content, clause 5.2 also has procedural requirements for the policy: it must be available as documented information, it must be communicated within the organization, and it must be available to interested parties, as appropriate. "Communicated" means more than being stored on a shared drive — auditors expect evidence that employees are actually aware of the policy, typically through induction training, periodic refreshers, or an acknowledgment/sign-off process.
Common structure of a compliant top-level information security policy
Most organizations structure the policy as a short document (one to three pages) that covers: purpose and scope of the ISMS; a statement of management commitment; the high-level security objectives or a reference to where they are documented; a commitment to legal, regulatory and contractual compliance; a commitment to continual improvement; roles referenced at a high level (with detail delegated to 5.3 and job descriptions); and a review cycle with a named owner. Longer, highly technical detail belongs in the topic-specific policies under Annex A, not in this top-level document.
5.3 Organizational roles, responsibilities and authorities
Clause 5.3 requires top management to ensure that the responsibilities and authorities for roles relevant to information security are assigned and communicated within the organization. Two responsibilities are called out explicitly by the standard because they are structurally important to how the ISMS demonstrates conformity and improvement:
- Ensuring the ISMS conforms to the requirements of ISO/IEC 27001 — someone must own the day-to-day question of whether the management system, as operated, actually satisfies the standard.
- Reporting on the performance of the ISMS to top management — someone must be responsible for surfacing ISMS performance data (incidents, audit results, risk treatment progress, metrics) up to leadership, so that clause 5.1's "ensure the ISMS achieves its intended outcomes" has something concrete to act on.
In practice, organizations satisfy 5.3 through a combination of: an ISMS Manager or Information Security Manager role with a documented job description; an org chart or RACI matrix showing security-relevant responsibilities across departments (IT, HR, legal, facilities, procurement); asset and risk owners assigned as individuals, not generic teams; and incident response roles defined ahead of an actual incident, not improvised during one. A common gap auditors find is a title on an org chart with no corresponding documented authority — for example, a "Data Protection & Security Officer" who has never been given explicit authority to halt a noncompliant process or reject a risky supplier contract.
How clause 5 connects to the rest of the ISMS
Clause 5 is not self-contained — it is the hinge between clause 4 (context) and everything that follows:
| Clause 5 element |
Feeds into |
Why it matters |
| Policy objectives (5.2) |
Clause 6.2 — information security objectives |
Objectives set at the planning stage must trace back to the policy commitments made here |
| Resourcing commitment (5.1) |
Clause 7 — support (resources, competence) |
Without leadership committing resources, clause 7 requirements cannot realistically be met |
| Risk and asset owners (5.3) |
Clause 6.1 — risk assessment and treatment |
Every risk identified in 6.1 needs a named owner assigned under 5.3 |
| ISMS conformity reporting (5.3) |
Clause 9 — performance evaluation, management review |
The person reporting ISMS performance under 5.3 is usually the one preparing management review inputs under 9.3 |
Common audit findings on clause 5
These are the nonconformities and observations that recur most often against clause 5 in ISMS surveillance and certification audits:
- 5.1 — No visible leadership involvement beyond sign-off: the CEO or director signed the policy once, but cannot describe in the audit interview what the current top information security risks are or what was discussed at the last management review.
- 5.2 — Policy not actually communicated: the policy exists as a PDF on a document management system, but new hires were never walked through it and there is no acknowledgment record.
- 5.2 — Policy never reviewed: the policy has a "next review date" field that has quietly passed, or the document has not changed in several years despite the business, its risks, or its regulatory environment having changed.
- 5.3 — Responsibilities exist informally only: "everyone knows" who handles incidents or who owns supplier risk, but nothing is written down, so there is no auditable evidence and no continuity if that person leaves.
- 5.3 — Authority without resourcing, or resourcing without authority: a security role is created on paper but given no budget, no time allocation, or no actual decision-making power — a classic sign the appointment was made to satisfy the audit rather than to run the ISMS.
// Demo IgeraIndustria — ISMS leadership and roles query
ISMS Manager: When was the information security policy last reviewed, and who is the current risk owner for the customer database?
IgeraIndustria: Information Security Policy v3.2 — last reviewed 14/02/2026, next review due 14/02/2027, approved by Managing Director. Risk owner for asset "Customer Database (Production)": M. Ferrer, IT Operations Lead, assigned 03/11/2025. Related open risk: R-2026-014, unauthorized access via legacy admin account, treatment status: in progress, due 30/08/2026.
Auditor: Show me evidence that the policy was communicated to staff, not just published.
IgeraIndustria: Policy v3.2 communication record: distributed via induction training to 14 new hires between March and June 2026, with signed acknowledgment on file for each. Annual refresher completed by 47 of 49 active employees as of 20/07/2026; 2 pending, reminder scheduled 25/07/2026.
Frequently asked questions about ISO 27001 clause 5
Who counts as "top management" for clause 5 of ISO 27001?
ISO defines top management as the person or group of people who direct and control the organization at the highest level within the scope of the ISMS. In a small or medium enterprise this is usually the owner, managing director or executive committee. In a larger organization it may be a business unit head if the ISMS scope is limited to that unit. What matters to auditors is that the individuals identified genuinely have the authority to allocate resources and set direction for the scoped organization — a delegated IT manager with no budget authority and no seat at leadership meetings typically does not qualify on their own.
No. ISO 27001 clause 5.2 requires a top-level information security policy with specific content, but it does not prescribe a single-document format. Many organizations maintain one short top-level policy addressing the clause 5.2 requirements, supported by a set of separate topic-specific policies (access control, acceptable use, cryptography, supplier security, and so on) referenced in Annex A. What is not acceptable is having only the detailed topic-specific policies with no overarching statement of objectives, scope and management commitment.
ISO 27001 does not mandate a specific review interval; it requires the policy to be maintained and kept suitable, adequate and effective, which in practice means a defined review cycle owned by someone. Annual review aligned with the management review cycle (clause 9.3) is the most common approach, with additional ad hoc reviews triggered by significant changes — a new regulatory requirement, a material incident, a merger or acquisition, or a significant change in the risk environment.
Yes, and in smaller organizations this is common — a single ISMS Manager or Information Security Officer often holds both responsibilities. ISO 27001 does not require segregation between these two responsibilities the way it requires segregation of duties for certain security controls in Annex A. What matters is that both responsibilities are clearly assigned, documented and communicated, and that the person holding them has genuine access to top management and genuine authority over ISMS conformity matters.
What is the difference between clause 5.1 leadership commitment and the policy required under 5.2?
Clause 5.1 is about ongoing behavior — demonstrable actions top management takes over time to drive, resource and champion the ISMS. Clause 5.2 is about a specific artifact — the written information security policy and its required content, communication and maintenance. A signed policy satisfies part of 5.2 but says nothing on its own about 5.1; auditors will ask separately for evidence of leadership behavior (meeting minutes, resourcing decisions, communications) beyond the policy document itself.
ISO 27001 does not require a specific document format for 5.3, but it does require that responsibilities and authorities are assigned and communicated, and an auditor will ask for evidence of both. Formal job descriptions, an ISMS roles and responsibilities matrix, or an approved organization chart annotated with security responsibilities are all acceptable, provided the people named in them can confirm in interview that they know what they are responsible for and have actually been given the authority (and resources) to do it.
Struggling to keep policy reviews, role assignments and management review evidence audit-ready?
IgeraIndustria centralizes ISMS documentation, policy review cycles, role assignments and risk ownership in one place — with real-time status instead of scattered spreadsheets and shared drives.
See the ISO 27001 solution
Expert ISO 27001 · Updated 2026-07-31 · ISO 27001 step-by-step series: Article 1 — Clause 4: Context of the Organization · Article 3 — Clause 6: Planning and Risk Assessment