\n\n","wordCount":2782,"timeToRead":"PT9M","keywords":["iso 27001 clause 5","iso 27001 leadership","information security policy iso 27001","isms roles and responsibilities","calidad-industrial","blog","RAG","IA","inteligencia artificial"]}
calidad-industrial

ISO 27001 Clause 5: Leadership, Information Security Policy and Roles

Expert ISO 27001
July 31, 2026
9 min read
Top management leadership and information security policy under ISO 27001 clause 5

ISO 27001 · Step-by-step series · Article 2 of 7

ISO 27001 Clause 5: Leadership, Information Security Policy and Roles

Clause 5 of ISO/IEC 27001:2022 is where an Information Security Management System (ISMS) stops being a document exercise and becomes a management commitment. It sets out what top management must actually do — not just approve — and it requires the organization to put in writing what it wants to achieve on information security and who is accountable for making that happen. Auditors treat clause 5 as a leading indicator: an ISMS with weak leadership evidence almost always shows weaker evidence everywhere else, because policy, resourcing and accountability cascade down from this clause.

Leadership and roles are consistently among the most-cited nonconformities in ISMS certification audits

Across ISO/IEC 27001 certification bodies, auditors routinely flag information security policies that were written once, never reviewed, and never actually communicated beyond the IT department, together with responsibility assignments that exist only informally. Neither failure is expensive to fix — both are almost entirely about documented intent and consistent practice, not technology.

The structure of clause 5: three connected requirements

Clause 5 of ISO 27001:2022 has three subclauses, and they build on each other in a specific order:

  • 5.1 Leadership and commitment: what top management must demonstrably do to drive the ISMS, not merely fund it.
  • 5.2 Policy: the information security policy itself — its required content, and how it must be established, communicated and maintained.
  • 5.3 Organizational roles, responsibilities and authorities: who is accountable for what within the ISMS, assigned and communicated by top management.

Unlike clause 4 (context of the organization), which is largely about analysis and scoping, clause 5 is about visible, ongoing management action. Auditors look for behavior and evidence over time — meeting minutes, policy revision history, org charts, job descriptions — not a single signed statement.

5.1 Leadership and commitment: what top management must actually do

Clause 5.1 lists specific actions top management must demonstrate — this is one of the more prescriptive leadership clauses across ISO management system standards, because information security failures are frequently traced back to leadership treating the ISMS as a delegated IT concern rather than a business risk owned at the top. ISO 27001:2022 requires top management to:

  • Ensure the information security policy and information security objectives are established and compatible with the strategic direction of the organization.
  • Ensure the integration of ISMS requirements into the organization's business processes — security cannot live in a silo separate from how the business actually operates.
  • Ensure the resources needed for the ISMS are available — budget, personnel, tooling, and time.
  • Communicate the importance of effective information security management and of conforming to the ISMS requirements.
  • Ensure the ISMS achieves its intended outcome(s).
  • Direct and support persons to contribute to the effectiveness of the ISMS.
  • Promote continual improvement.
  • Support other relevant management roles to demonstrate leadership as it applies to their areas of responsibility.

Practical tip

You do not need a standalone "leadership commitment" document to satisfy 5.1. What auditors actually want is evidence woven into normal business rhythm: information security as a standing agenda item in management review meetings, security objectives referenced in departmental goals, and a resourcing decision (a hire, a tool purchase, a training budget line) that traces back to an identified ISMS need. If leadership commitment only exists on paper and never surfaces in a meeting minute or a budget approval, that is exactly what an auditor will probe.

5.2 Information security policy: what it must contain

Clause 5.2 requires top management to establish an information security policy. This is the top-level policy for the whole ISMS — distinct from, and sitting above, the more detailed topic-specific policies referenced in Annex A (such as access control, cryptography, or supplier relationships policies). The clause specifies that the policy must:

  • Be appropriate to the purpose of the organization — a policy copied from a template with no reference to what the organization actually does will not withstand scrutiny.
  • Include information security objectives, or provide the framework for setting them — the policy either states measurable objectives directly or explains how they will be set (linking forward to clause 6.2).
  • Include a commitment to satisfy applicable requirements related to information security — legal, regulatory, contractual and other requirements identified under clause 4.2.
  • Include a commitment to continual improvement of the ISMS.

Beyond content, clause 5.2 also has procedural requirements for the policy: it must be available as documented information, it must be communicated within the organization, and it must be available to interested parties, as appropriate. "Communicated" means more than being stored on a shared drive — auditors expect evidence that employees are actually aware of the policy, typically through induction training, periodic refreshers, or an acknowledgment/sign-off process.

Common structure of a compliant top-level information security policy

Most organizations structure the policy as a short document (one to three pages) that covers: purpose and scope of the ISMS; a statement of management commitment; the high-level security objectives or a reference to where they are documented; a commitment to legal, regulatory and contractual compliance; a commitment to continual improvement; roles referenced at a high level (with detail delegated to 5.3 and job descriptions); and a review cycle with a named owner. Longer, highly technical detail belongs in the topic-specific policies under Annex A, not in this top-level document.

5.3 Organizational roles, responsibilities and authorities

Clause 5.3 requires top management to ensure that the responsibilities and authorities for roles relevant to information security are assigned and communicated within the organization. Two responsibilities are called out explicitly by the standard because they are structurally important to how the ISMS demonstrates conformity and improvement:

  • Ensuring the ISMS conforms to the requirements of ISO/IEC 27001 — someone must own the day-to-day question of whether the management system, as operated, actually satisfies the standard.
  • Reporting on the performance of the ISMS to top management — someone must be responsible for surfacing ISMS performance data (incidents, audit results, risk treatment progress, metrics) up to leadership, so that clause 5.1's "ensure the ISMS achieves its intended outcomes" has something concrete to act on.

In practice, organizations satisfy 5.3 through a combination of: an ISMS Manager or Information Security Manager role with a documented job description; an org chart or RACI matrix showing security-relevant responsibilities across departments (IT, HR, legal, facilities, procurement); asset and risk owners assigned as individuals, not generic teams; and incident response roles defined ahead of an actual incident, not improvised during one. A common gap auditors find is a title on an org chart with no corresponding documented authority — for example, a "Data Protection & Security Officer" who has never been given explicit authority to halt a noncompliant process or reject a risky supplier contract.

How clause 5 connects to the rest of the ISMS

Clause 5 is not self-contained — it is the hinge between clause 4 (context) and everything that follows:

Clause 5 element Feeds into Why it matters
Policy objectives (5.2) Clause 6.2 — information security objectives Objectives set at the planning stage must trace back to the policy commitments made here
Resourcing commitment (5.1) Clause 7 — support (resources, competence) Without leadership committing resources, clause 7 requirements cannot realistically be met
Risk and asset owners (5.3) Clause 6.1 — risk assessment and treatment Every risk identified in 6.1 needs a named owner assigned under 5.3
ISMS conformity reporting (5.3) Clause 9 — performance evaluation, management review The person reporting ISMS performance under 5.3 is usually the one preparing management review inputs under 9.3

Common audit findings on clause 5

These are the nonconformities and observations that recur most often against clause 5 in ISMS surveillance and certification audits:

  • 5.1 — No visible leadership involvement beyond sign-off: the CEO or director signed the policy once, but cannot describe in the audit interview what the current top information security risks are or what was discussed at the last management review.
  • 5.2 — Policy not actually communicated: the policy exists as a PDF on a document management system, but new hires were never walked through it and there is no acknowledgment record.
  • 5.2 — Policy never reviewed: the policy has a "next review date" field that has quietly passed, or the document has not changed in several years despite the business, its risks, or its regulatory environment having changed.
  • 5.3 — Responsibilities exist informally only: "everyone knows" who handles incidents or who owns supplier risk, but nothing is written down, so there is no auditable evidence and no continuity if that person leaves.
  • 5.3 — Authority without resourcing, or resourcing without authority: a security role is created on paper but given no budget, no time allocation, or no actual decision-making power — a classic sign the appointment was made to satisfy the audit rather than to run the ISMS.

// Demo IgeraIndustria — ISMS leadership and roles query

ISMS Manager: When was the information security policy last reviewed, and who is the current risk owner for the customer database?

IgeraIndustria: Information Security Policy v3.2 — last reviewed 14/02/2026, next review due 14/02/2027, approved by Managing Director. Risk owner for asset "Customer Database (Production)": M. Ferrer, IT Operations Lead, assigned 03/11/2025. Related open risk: R-2026-014, unauthorized access via legacy admin account, treatment status: in progress, due 30/08/2026.

Auditor: Show me evidence that the policy was communicated to staff, not just published.

IgeraIndustria: Policy v3.2 communication record: distributed via induction training to 14 new hires between March and June 2026, with signed acknowledgment on file for each. Annual refresher completed by 47 of 49 active employees as of 20/07/2026; 2 pending, reminder scheduled 25/07/2026.

Frequently asked questions about ISO 27001 clause 5

Who counts as "top management" for clause 5 of ISO 27001?

ISO defines top management as the person or group of people who direct and control the organization at the highest level within the scope of the ISMS. In a small or medium enterprise this is usually the owner, managing director or executive committee. In a larger organization it may be a business unit head if the ISMS scope is limited to that unit. What matters to auditors is that the individuals identified genuinely have the authority to allocate resources and set direction for the scoped organization — a delegated IT manager with no budget authority and no seat at leadership meetings typically does not qualify on their own.

Does the information security policy have to be a single document?

No. ISO 27001 clause 5.2 requires a top-level information security policy with specific content, but it does not prescribe a single-document format. Many organizations maintain one short top-level policy addressing the clause 5.2 requirements, supported by a set of separate topic-specific policies (access control, acceptable use, cryptography, supplier security, and so on) referenced in Annex A. What is not acceptable is having only the detailed topic-specific policies with no overarching statement of objectives, scope and management commitment.

How often must the information security policy be reviewed?

ISO 27001 does not mandate a specific review interval; it requires the policy to be maintained and kept suitable, adequate and effective, which in practice means a defined review cycle owned by someone. Annual review aligned with the management review cycle (clause 9.3) is the most common approach, with additional ad hoc reviews triggered by significant changes — a new regulatory requirement, a material incident, a merger or acquisition, or a significant change in the risk environment.

Can one person hold both the role that ensures ISMS conformity and the role that reports to top management under clause 5.3?

Yes, and in smaller organizations this is common — a single ISMS Manager or Information Security Officer often holds both responsibilities. ISO 27001 does not require segregation between these two responsibilities the way it requires segregation of duties for certain security controls in Annex A. What matters is that both responsibilities are clearly assigned, documented and communicated, and that the person holding them has genuine access to top management and genuine authority over ISMS conformity matters.

What is the difference between clause 5.1 leadership commitment and the policy required under 5.2?

Clause 5.1 is about ongoing behavior — demonstrable actions top management takes over time to drive, resource and champion the ISMS. Clause 5.2 is about a specific artifact — the written information security policy and its required content, communication and maintenance. A signed policy satisfies part of 5.2 but says nothing on its own about 5.1; auditors will ask separately for evidence of leadership behavior (meeting minutes, resourcing decisions, communications) beyond the policy document itself.

Do roles and responsibilities under clause 5.3 need to be in formal job descriptions?

ISO 27001 does not require a specific document format for 5.3, but it does require that responsibilities and authorities are assigned and communicated, and an auditor will ask for evidence of both. Formal job descriptions, an ISMS roles and responsibilities matrix, or an approved organization chart annotated with security responsibilities are all acceptable, provided the people named in them can confirm in interview that they know what they are responsible for and have actually been given the authority (and resources) to do it.

Struggling to keep policy reviews, role assignments and management review evidence audit-ready?

IgeraIndustria centralizes ISMS documentation, policy review cycles, role assignments and risk ownership in one place — with real-time status instead of scattered spreadsheets and shared drives.

See the ISO 27001 solution

Expert ISO 27001 · Updated 2026-07-31 · ISO 27001 step-by-step series: Article 1 — Clause 4: Context of the Organization · Article 3 — Clause 6: Planning and Risk Assessment

#iso 27001 clause 5#iso 27001 leadership#information security policy iso 27001#isms roles and responsibilities

COMPARTIR

Comparte el conocimiento con tu red