Back to Columns
ISMS & Certification11 min read

ISO/IEC 27001 Clause 5: Leadership and Top Management's Responsibility

September 14, 2026

ISO/IEC 27001 Clause 5: Leadership and Top Management's Responsibility
Share this article

"The CEO has already signed off." It is the standard reply when Clause 5 comes up in an ISMS conversation. But what the standard asks of the executive team is not a signature — it is accountability for the ISMS actually working. That difference decides both audit outcomes and whether the system survives certification.

Organisations whose ISMS hollows out after certification share a pattern: one person runs it, information security never appears on the executive agenda, and resource requests die at "not this quarter." Clause 5 exists precisely to prevent that state.

This article translates Clause 5 into practice: writing the policy, assigning roles and authority, and what the management interview tests. For the prerequisite scope work see Clause 4: Context of the Organisation; for the whole standard, What Is an ISMS (ISO/IEC 27001)?.

Disclaimer: This article is general information. The authoritative texts are ISO/IEC 27001 (JIS Q 27001) itself and the publications of the accreditation and certification bodies. Base actual decisions on those.

What This Clause Actually Asks For

Clause 5 has three parts.

1. Leadership and commitment

A list of what top management must do. In substance:

  • Set policy and objectives, and align them with the organisation's strategic direction
  • Integrate ISMS requirements into everyday business processes
  • Provide the resources the ISMS needs — people, time, budget, tooling
  • Communicate why information security management and conformity matter
  • Ensure the ISMS achieves its intended outcomes
  • Direct and support people to contribute to it
  • Promote continual improvement
  • Support other managers in exercising leadership within their own areas

The decisive item is integration into business processes. As long as the ISMS is a separate activity running alongside real work, this requirement is not met. Integration means a security check sits inside the product planning review; a security requirement check sits inside the supplier contracting flow.

2. Policy

Establish an information security policy, document it, communicate it internally, and make it available to interested parties as appropriate. It must be appropriate to the organisation's purpose, provide a framework for setting security objectives, and commit to satisfying applicable requirements and to continual improvement.

3. Roles, responsibilities and authorities

Assign and communicate responsibilities and authorities for information security roles. In particular, responsibility for ensuring the ISMS conforms to the standard and for reporting ISMS performance to top management must be clearly assigned.

What You Produce in Practice

DeliverablePurposeWho approves
Information security policyDeclares direction; frames objective-settingTop management
Record of policy communicationEvidence it reached all workers (distribution logs, training records, postings)ISMS manager
ISMS organisation chartMakes visible who holds which roleTop management
Roles, responsibilities and authorities registerDefines each role's remit and decision rights in wordsTop management
Appointment recordsEvidence of appointing the ISMS manager, internal audit manager, etc.Top management
Resource provision recordsBudget approvals, staffing decisions, tooling purchasesTop management
Management review minutesEvidence that executives reviewed ISMS status and issued directionTop management

Note the pattern: top management approves nearly everything Clause 5 produces. Organisations that let a delegate sign in their place get challenged at audit.

Writing the policy

Longer is not better. One A4 page, two at most. What belongs in it:

  1. Why the organisation pursues information security (connection to business purpose)
  2. What is being protected (connection to scope)
  3. A commitment to meet applicable legal and contractual requirements
  4. A commitment to set and review information security objectives
  5. A commitment to continual improvement
  6. That all workers are obliged to comply
  7. Issue date, revision date, and the approving executive by name

What to avoid is a policy composed entirely of sentences that would fit any company. For a healthcare company, a single line about responsibility as a custodian of medical and patient information makes the policy yours. See Writing an Information Security Policy.

Assigning roles

In small organisations the CEO sometimes also serves as ISMS manager. Nothing forbids it, but it makes the reporter and the recipient of the report the same person, which is hard to justify as an effective reporting line. It is usually cleaner to place another executive or a department head as ISMS manager, with the CEO receiving reports as top management.

Internal audit manager and internal auditors can be outsourced. See ISMS for Small Organisations.

Where It Goes Wrong

The signature is the whole of it

The most common pattern: a signed policy, and not one executive meeting minute mentioning information security. Auditors see this. The minimum fix is a standing ISMS item on the executive agenda, even quarterly.

Reading "integration into business processes" as a documentation task

Integration means decision points embedded in existing workflows, not documents produced.

Existing workflowWhat integration looks like
New service planning approvalThe plan template carries a risk assessment section, and it is an approval condition
Supplier selectionSecurity requirements sit in the selection criteria; check-sheet results attach to the approval
OnboardingTraining completion and signed undertaking precede account issuance
OffboardingAccount disablement and device recovery always run on the leaving date
Incident reportingCriteria for classifying something as a security incident live inside the same flow

Resource requests never reach the executives

The standard requires providing necessary resources, but frequently no request was ever escalated. Defining the route for requesting resources and the record of the decision is what bridges Clause 5 to management review in Clause 9.

Roles without authority

Someone holds the title "ISMS manager" but cannot commit budget or assign people. Write authority — what the role may decide — not just responsibility.

The policy never reaches employees

Posting it on an intranet is weak evidence of communication. Have it read inside training and keep completion records, so arrival can be confirmed. See Designing Security Awareness Training.

What Auditors Look At

Clause 5 is usually examined through a management interview at stage 2 — 30 to 60 minutes with top management directly.

Question intentWhat it tests
What are your information security risks?Whether executives themselves know, rather than deferring to staff
Why does this organisation run an ISMS?Whether strategy alignment can be stated in the executive's own words
What are this year's security objectives?Whether objectives are an executive concern
What resources have you provided?Whether there is concrete evidence of budget and staffing
Were you briefed on the last incident?Whether the reporting line functions
What direction did you give at management review?Whether direction was given and tracked

Specificity matters more than polish. "We consider security important" scores differently from "supplier management was our weak point last year, so this year I allocated effort to revising the check sheet."

Preparation — handing the executives likely questions in advance and rehearsing once — changes the quality of this interview substantially. See What Stage 2 Audits Look At and Common Nonconformities.

Healthcare Examples

A healthcare SaaS provider

Here executive involvement is itself a condition of trade. Hospital procurement may ask about the executive structure accountable for security, and "our staff cannot answer that" does happen. Stating custodial responsibility for medical information in the policy, and reviewing inbound customer security enquiries and their status at executive meetings, makes both sales and operations work.

A PHR operator

Because data comes directly from individuals, whether the policy contains a commitment not to use data beyond the user's consent is a substantive decision. If it does, the supporting operation — request-and-approval flow for data use, logging — must exist. A commitment contradicted by practice becomes grounds for a finding against the policy itself.

A clinical trial systems company

You sit under two external examinations: regulatory inspection and certification audit. Unless the roles register draws the boundary between quality assurance and the ISMS manager, it becomes unclear under whose authority a record was approved.

A SaMD developer

When the QMS management representative and the ISMS manager are different people, one design change runs through two approval routes. Tabulate, at the roles stage, which documents need which approval. See SaMD, ISMS and QMS.

Across all of these, the constant is that executives can say in their own words what the organisation's most important asset to protect is. See Scope Design for Healthcare Companies and, for the buyer's view, Security Check Sheets for Vendors.

Conclusion

  1. Clause 5 asks for executive accountability for effectiveness, not a signature. Integration into business processes is the core
  2. Top management approves nearly every Clause 5 deliverable; delegated approval gets challenged
  3. The policy is one or two pages. Its quality turns on whether one sentence is specific to you
  4. The roles register must state authority — what may be decided — not only responsibility
  5. Clause 5 is audited mainly through the management interview, where specificity beats polish
  6. The minimum implementation is a standing ISMS item on the executive agenda

The direction set here becomes concrete objectives and risk treatment in Clause 6: Planning, and a foundation of people and documents in Clause 7: Support. Execution is Clause 8: Operation, checking is Clause 9: Performance Evaluation, and improvement is Clause 10.

Pottech supports ISMS certification with a focus on healthcare, including preparing executives for the management interview and designing the policy and organisation chart. See ISMS Certification Support or contact us.

References and Sources

Note: interpretation of requirements and the handling of accreditation and certification are governed by the standard itself and by the publications of the accreditation and certification bodies, and may change with revisions.

Share this article

Related Articles

ISMS & Certification

Reading the 37 Organizational Controls

The 37 organizational controls of Annex A.5, grouped into eight clusters rather than translated one by one: policy and governance, assets and classification, access policy, suppliers and cloud, threat intelligence, incident management, continuity, and compliance. What each cluster is asking for, and what you end up producing.

September 14, 2026
ISMS & Certification

Annex A 2022: 93 Controls Across Four Themes

A map of the 93 Annex A controls in ISO/IEC 27001:2022 across four themes — 37 organizational, 8 people, 14 physical, 34 technological. Why there is no duty to implement all 93, how inclusion and exclusion are justified in the Statement of Applicability, what the attributes are for, and the order a healthcare company should work in.

September 14, 2026
ISMS & Certification

Reading the 8 People Controls

The 8 people controls of Annex A.6, grouped into entry, employment, exit, where people work, and reporting culture. How they connect to existing employment rules, how to handle segregation of duties when the team is too small for it, and how far to go on remote working — written for healthcare companies.

September 14, 2026
ISMS & Certification

Reading the 14 Physical Controls

The 14 physical controls of Annex A.7 in five clusters, with a concrete treatment of what a fully remote, cloud-only organisation can exclude and what must be reassigned to home-working rules and supplier management — data centres, media and disposal, and equipment off premises.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.