Management responsibilities
Purpose
Make sure managers understand their part in security and drive their staff to be aware of and meet their security obligations.
How to meet this control
In short: Require all personnel to apply security per established policies and procedures.
- Step 01Embed security obligations into employment contracts and the staff handbook so the duty to comply is contractual, not just advisory
- Step 02Have managers complete a short induction confirming they have briefed each new report on role-specific security expectations before access is granted
- Step 03Provide managers a checklist of their security duties (approve access promptly, report leavers, escalate incidents) and track completion
- Step 04Stand up a confidential or anonymous reporting channel (hotline, dedicated mailbox or web form) for policy violations
- Step 05Build security tasks into resourcing and project plans so teams are given time and budget to meet obligations
Tip: Reference the policies in employment terms and onboarding.
What ISO 27002 says to cover
Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.
- ›Have managers visibly support the security policies, procedures and controls
- ›Brief personnel on their security roles before giving them access to assets
- ›Give staff clear guidance on the security expectations of their role
- ›Require staff to follow the organisation's policies and meet the security terms of their contracts
- ›Keep staff skills current through ongoing security training and education
- ›Provide a confidential or anonymous channel for reporting policy violations
- ›Allocate enough resources and planning time for staff to implement security processes and controls
Audit evidence to keep
- - Employment contract or handbook clauses requiring compliance with security policies
- - Manager onboarding briefing records confirming staff were informed of their duties
- - Evidence of a functioning confidential reporting channel and its usage guidance
- - Management communications reinforcing security expectations to staff
Common mistakes
- - Writing a policy but not operating the process
- - Keeping evidence in personal folders where auditors cannot trace it
- - Letting exceptions stay open with no owner or expiry date
Owner, cadence, and proof
Assign one accountable owner for A.5.4. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.