Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 5.4

Management Responsibilities: A Practical Implementation Guide

Managers turn security policies into daily expectations by directing, supporting and checking the people for whom they are responsible.

Control 5.4 addresses management's responsibility to ensure that personnel apply information security in accordance with the organization's established policies and procedures. The emphasis is operational: managers must actively reinforce security before, during and after employment or engagement.

Practical interpretation: Publishing policies and sending annual training are not sufficient. Line managers influence access, priorities, workload, behaviour and exceptions. They need defined security actions within normal people-management processes.

What should managers actually do?

  • Explain relevant security expectations before access is granted.
  • Ensure personnel understand their responsibilities and receive appropriate training.
  • Authorize access according to business need and review it when roles change.
  • Provide adequate time and resources for security tasks.
  • Identify and address non-compliance consistently.
  • Escalate incidents, risks and exceptions through defined channels.
  • Ensure responsibilities and assets are handed over when engagement changes or ends.

Step-by-step implementation

1

Translate policy into manager actions

Create a short management security checklist rather than expecting every manager to interpret the ISMS alone. Link actions to recruitment, onboarding, access approval, performance management, role changes, remote work and termination.

2

Define expectations before access

Before a person receives systems or information, the manager confirms the role, required access, confidentiality obligations and mandatory training. Access should follow approved role profiles or be justified individually.

3

Brief people on role-specific responsibilities

General awareness is a baseline. Managers should explain the security requirements most relevant to the role—for example secure coding for developers, customer-data handling for support staff or supplier due diligence for procurement.

4

Supervise and reinforce behaviour

Include security in team meetings, one-to-ones and operational decisions. Managers should challenge unsafe shortcuts, recognize good reporting behaviour and ensure deadlines do not routinely override security requirements.

5

Manage role changes promptly

When responsibilities change, managers trigger access adjustment, asset transfer and updated training. Do not wait for a periodic review to remove privileges that are no longer required.

6

Handle non-compliance consistently

Managers document concerns, involve HR and Information Security where appropriate, and follow the disciplinary process. Distinguish accidental mistakes, unclear rules, inadequate training and deliberate misconduct.

7

Complete secure offboarding

Managers notify relevant functions in time, identify accounts and assets, transfer business information, preserve records and confirm return of equipment. High-risk departures may require immediate coordinated action.

8

Monitor management performance

Track overdue approvals, access reviews, training, offboarding tasks and repeated policy exceptions by team. Use the results to improve processes and provide targeted support—not merely to assign blame.

Example management lifecycle

StageManager actionEvidence
Before startConfirm role, access profile, location, equipment and confidentiality needs.Approved onboarding request
First weekExplain team-specific security rules and ensure required training is completed.Checklist and training record
During engagementReview access, address unsafe behaviour and escalate incidents or exceptions.Access review, meeting record, tickets
Role changeRemove obsolete access, approve new access and arrange additional training.Change workflow and access log
TerminationCoordinate account closure, asset return, handover and continuing obligations.Completed offboarding checklist

What this could look like in practice

Example: manager onboarding a customer support analyst

The manager selects the approved “Support Analyst” access profile and documents why access to the ticketing and customer portals is required. The analyst completes general security and privacy training before production access. During a team briefing, the manager explains identity verification, restrictions on exporting customer data, event reporting and the approved method for sharing files.

After 30 days, the manager confirms that the assigned access remains appropriate. If the analyst moves to Quality Assurance, the manager initiates a mover workflow that removes customer-edit permissions before the new role begins. The workflow retains approval and completion timestamps.

Example: urgent operational exception

A team wants to use an unapproved collaboration tool to meet a deadline. The manager does not quietly permit it. Instead, the manager submits a time-limited exception describing the business need, data involved, risks and proposed safeguards. Information Security and the risk owner approve or reject the request, and the exception is tracked to expiry.

Manager security checklist

  • Confirm role and access need
  • Use approved access profiles
  • Verify mandatory training
  • Explain role-specific rules
  • Encourage prompt incident reporting
  • Review access periodically
  • Trigger changes without delay
  • Document policy exceptions
  • Address repeated unsafe behaviour
  • Protect personnel confidentiality
  • Coordinate asset handover
  • Complete offboarding evidence

Evidence checklist

  • Management responsibility policy
  • Manager onboarding guidance
  • Joiner/mover/leaver workflows
  • Access approval records
  • Role-specific briefing records
  • Training completion reports
  • Periodic access reviews
  • Exception approvals
  • Documented escalations
  • Performance or disciplinary process links
  • Asset return records
  • Manager compliance reports

Useful metrics

  • Percentage of starters completing required training before privileged or production access
  • Percentage of access reviews completed by managers on time
  • Average time to remove access after a role change or termination
  • Number of overdue manager-owned security actions
  • Number of repeated policy exceptions by team
  • Percentage of offboarding checklists completed without missing assets or accounts

Common mistakes

  • Treating security as the CISO's job. Line managers control many day-to-day decisions and priorities.
  • Generic onboarding only. Personnel never learn the risks specific to their role.
  • Rubber-stamp access approval. Managers approve requests without understanding the permissions.
  • Late mover notifications. Old access accumulates after internal transfers.
  • Security loses to delivery pressure. Managers reward shortcuts while policies say the opposite.
  • No evidence. Informal conversations may be helpful but cannot demonstrate consistent operation.
  • Unequal enforcement. Senior or high-performing personnel are allowed to bypass rules without approved exceptions.

Questions an auditor may ask

  • What security actions are line managers required to perform?
  • Show a recent onboarding, role change and termination.
  • How do managers know which access is appropriate?
  • What happens when a person does not follow security policy?
  • How does management ensure workload and deadlines do not undermine controls?
  • How is completion of manager-owned actions monitored?
Implementation test: Choose one recent joiner, mover and leaver. Can the manager demonstrate timely access decisions, relevant briefing or training, asset handling and completion of every required security action?

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.