Back to all 93 controls
    Annex A 5.4
    Organizational

    A.5.4 Management responsibilities

    Management actively requires staff to apply security.

    What good looks like

    Leadership communicates expectations, enforces policies, and holds people accountable.

    Evidence an auditor will ask for

    Management briefings, performance objectives, disciplinary records.

    Reviewed & Verified by a Certified ISO/IEC 27001 Lead Implementer

    Built for practitioners, by practitioners. Every template, control definition, and audit checklist in this directory is aligned with the latest ISO 27001:2022 standard and structured around real-world certification audit requirements.

    Certified Lead Implementer
    2022 Standard Aligned
    Audit-Ready Materials

    Put this control into practice

    Check whether your organisation already meets Annex A 5.4 with the free Gap Analysis tool, or get implementation-ready templates for every Annex A control with the Document Pack.