Leadership
Top management must own the ISMS: demonstrate commitment, set the policy, and assign roles and authorities.
Mandatory documents in this clause
- ✓Information security policy (5.2)
Leadership and commitment
What it requires: Top management must demonstrate leadership by aligning the policy and objectives to strategy, integrating the ISMS into business processes, providing resources, communicating its importance, ensuring it achieves its outcomes, and promoting continual improvement.
How to meet it: Evidence this through approved policy, budget/headcount decisions, and management review minutes that show genuine involvement.
Policy
What it requires: Establish an information security policy appropriate to the organisation that includes (or frames) objectives and commitments to satisfy requirements and continually improve. It must be documented, communicated internally, and available to interested parties as appropriate.
How to meet it: A concise top-level policy, management-approved, published where staff can find it, and shareable with customers.
Roles, responsibilities and authorities
What it requires: Assign and communicate responsibilities and authorities for ISMS-relevant roles, including for ensuring conformance to the standard and reporting ISMS performance to top management.
How to meet it: A simple responsibility matrix; name who owns ISMS conformance and who reports performance upward.
ISO 27001 policy templates
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.