"The CEO has already signed off." It is the standard reply when Clause 5 comes up in an ISMS conversation. But what the standard asks of the executive team is not a signature — it is accountability for the ISMS actually working. That difference decides both audit outcomes and whether the system survives certification.
Organisations whose ISMS hollows out after certification share a pattern: one person runs it, information security never appears on the executive agenda, and resource requests die at "not this quarter." Clause 5 exists precisely to prevent that state.
This article translates Clause 5 into practice: writing the policy, assigning roles and authority, and what the management interview tests. For the prerequisite scope work see Clause 4: Context of the Organisation; for the whole standard, What Is an ISMS (ISO/IEC 27001)?.
Disclaimer: This article is general information. The authoritative texts are ISO/IEC 27001 (JIS Q 27001) itself and the publications of the accreditation and certification bodies. Base actual decisions on those.
What This Clause Actually Asks For
Clause 5 has three parts.
1. Leadership and commitment
A list of what top management must do. In substance:
- Set policy and objectives, and align them with the organisation's strategic direction
- Integrate ISMS requirements into everyday business processes
- Provide the resources the ISMS needs — people, time, budget, tooling
- Communicate why information security management and conformity matter
- Ensure the ISMS achieves its intended outcomes
- Direct and support people to contribute to it
- Promote continual improvement
- Support other managers in exercising leadership within their own areas
The decisive item is integration into business processes. As long as the ISMS is a separate activity running alongside real work, this requirement is not met. Integration means a security check sits inside the product planning review; a security requirement check sits inside the supplier contracting flow.
2. Policy
Establish an information security policy, document it, communicate it internally, and make it available to interested parties as appropriate. It must be appropriate to the organisation's purpose, provide a framework for setting security objectives, and commit to satisfying applicable requirements and to continual improvement.
3. Roles, responsibilities and authorities
Assign and communicate responsibilities and authorities for information security roles. In particular, responsibility for ensuring the ISMS conforms to the standard and for reporting ISMS performance to top management must be clearly assigned.
What You Produce in Practice
| Deliverable | Purpose | Who approves |
|---|---|---|
| Information security policy | Declares direction; frames objective-setting | Top management |
| Record of policy communication | Evidence it reached all workers (distribution logs, training records, postings) | ISMS manager |
| ISMS organisation chart | Makes visible who holds which role | Top management |
| Roles, responsibilities and authorities register | Defines each role's remit and decision rights in words | Top management |
| Appointment records | Evidence of appointing the ISMS manager, internal audit manager, etc. | Top management |
| Resource provision records | Budget approvals, staffing decisions, tooling purchases | Top management |
| Management review minutes | Evidence that executives reviewed ISMS status and issued direction | Top management |
Note the pattern: top management approves nearly everything Clause 5 produces. Organisations that let a delegate sign in their place get challenged at audit.
Writing the policy
Longer is not better. One A4 page, two at most. What belongs in it:
- Why the organisation pursues information security (connection to business purpose)
- What is being protected (connection to scope)
- A commitment to meet applicable legal and contractual requirements
- A commitment to set and review information security objectives
- A commitment to continual improvement
- That all workers are obliged to comply
- Issue date, revision date, and the approving executive by name
What to avoid is a policy composed entirely of sentences that would fit any company. For a healthcare company, a single line about responsibility as a custodian of medical and patient information makes the policy yours. See Writing an Information Security Policy.
Assigning roles
In small organisations the CEO sometimes also serves as ISMS manager. Nothing forbids it, but it makes the reporter and the recipient of the report the same person, which is hard to justify as an effective reporting line. It is usually cleaner to place another executive or a department head as ISMS manager, with the CEO receiving reports as top management.
Internal audit manager and internal auditors can be outsourced. See ISMS for Small Organisations.
Where It Goes Wrong
The signature is the whole of it
The most common pattern: a signed policy, and not one executive meeting minute mentioning information security. Auditors see this. The minimum fix is a standing ISMS item on the executive agenda, even quarterly.
Reading "integration into business processes" as a documentation task
Integration means decision points embedded in existing workflows, not documents produced.
| Existing workflow | What integration looks like |
|---|---|
| New service planning approval | The plan template carries a risk assessment section, and it is an approval condition |
| Supplier selection | Security requirements sit in the selection criteria; check-sheet results attach to the approval |
| Onboarding | Training completion and signed undertaking precede account issuance |
| Offboarding | Account disablement and device recovery always run on the leaving date |
| Incident reporting | Criteria for classifying something as a security incident live inside the same flow |
Resource requests never reach the executives
The standard requires providing necessary resources, but frequently no request was ever escalated. Defining the route for requesting resources and the record of the decision is what bridges Clause 5 to management review in Clause 9.
Roles without authority
Someone holds the title "ISMS manager" but cannot commit budget or assign people. Write authority — what the role may decide — not just responsibility.
The policy never reaches employees
Posting it on an intranet is weak evidence of communication. Have it read inside training and keep completion records, so arrival can be confirmed. See Designing Security Awareness Training.
What Auditors Look At
Clause 5 is usually examined through a management interview at stage 2 — 30 to 60 minutes with top management directly.
| Question intent | What it tests |
|---|---|
| What are your information security risks? | Whether executives themselves know, rather than deferring to staff |
| Why does this organisation run an ISMS? | Whether strategy alignment can be stated in the executive's own words |
| What are this year's security objectives? | Whether objectives are an executive concern |
| What resources have you provided? | Whether there is concrete evidence of budget and staffing |
| Were you briefed on the last incident? | Whether the reporting line functions |
| What direction did you give at management review? | Whether direction was given and tracked |
Specificity matters more than polish. "We consider security important" scores differently from "supplier management was our weak point last year, so this year I allocated effort to revising the check sheet."
Preparation — handing the executives likely questions in advance and rehearsing once — changes the quality of this interview substantially. See What Stage 2 Audits Look At and Common Nonconformities.
Healthcare Examples
A healthcare SaaS provider
Here executive involvement is itself a condition of trade. Hospital procurement may ask about the executive structure accountable for security, and "our staff cannot answer that" does happen. Stating custodial responsibility for medical information in the policy, and reviewing inbound customer security enquiries and their status at executive meetings, makes both sales and operations work.
A PHR operator
Because data comes directly from individuals, whether the policy contains a commitment not to use data beyond the user's consent is a substantive decision. If it does, the supporting operation — request-and-approval flow for data use, logging — must exist. A commitment contradicted by practice becomes grounds for a finding against the policy itself.
A clinical trial systems company
You sit under two external examinations: regulatory inspection and certification audit. Unless the roles register draws the boundary between quality assurance and the ISMS manager, it becomes unclear under whose authority a record was approved.
A SaMD developer
When the QMS management representative and the ISMS manager are different people, one design change runs through two approval routes. Tabulate, at the roles stage, which documents need which approval. See SaMD, ISMS and QMS.
Across all of these, the constant is that executives can say in their own words what the organisation's most important asset to protect is. See Scope Design for Healthcare Companies and, for the buyer's view, Security Check Sheets for Vendors.
Conclusion
- Clause 5 asks for executive accountability for effectiveness, not a signature. Integration into business processes is the core
- Top management approves nearly every Clause 5 deliverable; delegated approval gets challenged
- The policy is one or two pages. Its quality turns on whether one sentence is specific to you
- The roles register must state authority — what may be decided — not only responsibility
- Clause 5 is audited mainly through the management interview, where specificity beats polish
- The minimum implementation is a standing ISMS item on the executive agenda
The direction set here becomes concrete objectives and risk treatment in Clause 6: Planning, and a foundation of people and documents in Clause 7: Support. Execution is Clause 8: Operation, checking is Clause 9: Performance Evaluation, and improvement is Clause 10.
Pottech supports ISMS certification with a focus on healthcare, including preparing executives for the management interview and designing the policy and organisation chart. See ISMS Certification Support or contact us.
References and Sources
- Information Management System Accreditation Center (ISMS-AC)
- ISO/IEC 27001 Information security management systems | ISO
- Japanese Industrial Standards Committee (JISC)
- Guidelines for the Safe Management of Medical Information Systems | MHLW
Note: interpretation of requirements and the handling of accreditation and certification are governed by the standard itself and by the publications of the accreditation and certification bodies, and may change with revisions.