6.2 Clause 5: Leadership
Key Takeaways
- Clause 5 makes top management — not the IT department, not the CISO alone — ultimately accountable for the ISMS, a favorite exam emphasis
- 5.1 requires top management to demonstrate leadership and commitment by establishing policy, ensuring resources, communicating importance, and directing support
- The information security policy (5.2) must be appropriate to the organization's purpose, include commitments to applicable requirements and continual improvement, and be available as documented information
- 5.3 requires top management to assign roles, responsibilities, and authorities for the ISMS — including who reports on ISMS performance to top management
- Leadership is a Plan-stage activity: without it, scope, policy, and risk decisions lack the authority to be effective
If Clause 4 is the foundation, Clause 5 is the engine. ISO/IEC 27001:2022 places top management — not the IT department, not the security team — squarely in the driver's seat. The Foundation exam loves this clause because it separates organizations that have a management system from those that merely have security tools.
5.1 Leadership and Commitment
Top management must demonstrate leadership and commitment with respect to the ISMS. "Top management" is defined in ISO directives as a person or group of people who directs and controls an organization at the highest level — not necessarily a single role like a CEO, and definitely not the IT manager.
Specific Responsibilities
Top management must:
- Ensure that the information security policy and objectives are established and are compatible with the strategic direction of the organization
- Ensure the integration of the ISMS into the organization's business processes
- Ensure that the resources needed for the ISMS are available
- Communicate the importance of effective information security management and conformance to the ISMS requirements
- Ensure that the ISMS achieves its intended outcomes
- Direct and support persons to contribute to the effectiveness of the ISMS
- Promote continual improvement
- Support other relevant management roles to demonstrate leadership in their areas of responsibility
Why This Matters on the Exam
Exam scenarios often describe a security program that fails because top management treats the ISMS as a delegated IT initiative. Any answer that says top management's role is limited to "approving the budget" or "receiving an annual report" is wrong — leadership and commitment are active, ongoing obligations, not passive endorsements.
Resources and Communication — A Common Trap
Two specific 5.1 responsibilities show up frequently:
- Ensuring resources — budget, people, tools, training, time
- Communicating importance — making it clear across the organization that information security matters and conformance is expected
A trap answer like "the CISO communicates the importance of information security" is wrong unless the CISO is acting on behalf of, and with the authority of, top management.
5.2 Policy
Top management must establish an information security policy that:
- Is appropriate to the purpose of the organization (aligned with context from 4.1)
- Includes a commitment to satisfy applicable requirements related to information security (legal, regulatory, contractual, and other adopted requirements)
- Includes a commitment to continual improvement of the ISMS
- Provides a framework for setting information security objectives
- Is available as documented information
- Is communicated within the organization
- Is available to interested parties, as appropriate
Policy types the Foundation exam expects
PECB's Domain 2 knowledge statements distinguish policy levels you should recognize:
| Policy type | Role |
|---|---|
| High-level general | Broad organizational information security policy required by Clause 5.2 — direction from top management |
| High-level specific | Policies that set direction for a major domain (e.g., access control policy, cryptography policy) while remaining management-level |
| Topic-specific | Detailed policies for a particular subject (e.g., acceptable use, remote working, clear desk) that implement the high-level direction |
Annex A control A.5.1 Policies for information security expands this into a set of policies. Clause 5.2 is the mandatory high-level ISMS policy; topic-specific policies are selected through risk treatment and documented in the SoA where applicable.
Development life cycle (exam recognition)
A workable Foundation-level life cycle is: draft → review → top-management approval → publish/communicate → implement → monitor → review/update. Questions often test that approval and communication are top-management responsibilities (5.1/5.2), not optional IT tasks.
The Policy Framework Function
The policy itself is short — usually one or two pages. Its job is not to list controls but to provide a framework for setting objectives. That means objectives set under Clause 6.2 must be consistent with the commitments in the policy.
Documented Information Requirement
The policy must be available as documented information. This is a hard requirement — a verbal policy or a slide deck without a controlled document fails. The policy must also be communicated to persons in the organization and available to interested parties as appropriate (for example, published on a website or shared on request with customers).
Policy Content Trap
The exam may offer an option stating the policy must "list all applicable controls from Annex A." Wrong — the policy provides a framework; the specific controls come from the risk treatment process in 6.1.3 and the Statement of Applicability.
5.3 Organizational Roles, Responsibilities, and Authorities
Top management must ensure that the roles, responsibilities, and authorities relevant to information security are assigned and communicated within the organization.
Two specific assignments are mandatory:
- Responsibility for ensuring the ISMS conforms to the requirements of ISO/IEC 27001
- Responsibility for **reporting on the performance of the ISMS to top management"
Who Can Be Assigned?
There is no requirement that the assigned person be a CISO, ISO 27001 lead implementer, or any specific title. The assigned person can be any competent individual — what matters is that the role is defined, assigned, communicated, and accepted.
Reporting to Top Management
The reporting line is upward — the assigned person reports ISMS performance to top management. This is what enables top management to fulfil its 5.1 responsibility to ensure the ISMS achieves its intended outcomes and to conduct the management review required by Clause 9.3. The exam often frames this as a downward delegation "so top management does not need to be involved" — that is wrong. The reporting line keeps top management engaged.
How Clause 5 Connects to the Rest of the Standard
| Clause 5 Output | Used By |
|---|---|
| Policy (5.2) | 6.2 — must provide framework for objectives |
| Resources ensured (5.1) | 7.1 — Clause 7 expands on resources in detail |
| Roles assigned (5.3) | 7.2 — competence; 7.3 — awareness |
| Communication of importance (5.1) | 7.4 — communication |
| Performance reporting (5.3) | 9.1 — monitoring; 9.3 — management review |
| Continual improvement (5.1) | 10.1, 10.2 — improvement and nonconformity |
Clause 5 is short but it touches almost every later clause — which is why the exam treats it as a high-yield topic.
Exam Scenarios and Traps
- Trap 1: An option says the CISO alone establishes the information security policy. Wrong — top management establishes it. The CISO may draft it, but ownership is top management's.
- Trap 2: A scenario where the policy is included in the employee handbook but no controlled document exists. Wrong — the policy must be available as documented information, not embedded informally in another document.
- Trap 3: "Roles and responsibilities are assigned by the IT manager." Wrong — top management assigns them.
- Trap 4: An option states the policy must list every Annex A control. Wrong — the policy provides a framework; control selection happens via risk treatment.
- Trap 5: A scenario where the ISMS is delegated to a security committee that reports to the CFO, with no reporting to top management. Wrong — performance must be reported to top management.
Key Takeaways
- Top management — not the IT department — owns the ISMS under Clause 5.
- The policy must be appropriate, framework-setting, available as documented information, communicated, and available to interested parties.
- Roles, responsibilities, and authorities must be assigned by top management, including responsibility for reporting ISMS performance back to top management.
- Leadership and commitment are active obligations: ensuring resources, communicating importance, integrating with business processes, and promoting continual improvement.
Under Clause 5.1, which of the following is a specific responsibility of top management regarding the ISMS?
Which of the following is NOT a required content element of the information security policy under Clause 5.2?
An organization assigns a senior security manager as the person responsible for ensuring the ISMS conforms to ISO/IEC 27001. What additional assignment does Clause 5.3 require top management to make?