ISO 27001 guide · Plan
Clause 5 — Leadership
ISO 27001:2022 clause 5 covers leadership commitment, the information security policy and assigned roles: the accountability every other clause depends on.
By Sentrix · Published 2026-07-16
An ISMS that top management does not actively own is a documentation exercise, not a management system — and clause 5 is where the standard makes that ownership a certifiable requirement rather than a hope. It asks for demonstrated commitment from top management, not just sign-off; a published security policy that actually says something specific to your organization; and roles and authorities assigned clearly enough that when something goes wrong, everyone already knows whose job it is to respond. Auditors treat weak clause 5 evidence as a warning sign for the rest of the file, because a security program without genuine leadership backing rarely survives contact with competing business priorities.
What clause 5 covers
Clause 5 is flat — three requirements, no sub-clauses, like clauses 4, 8, and 10. 5.1 requires top management to actually demonstrate commitment to the ISMS, not just approve it once. 5.2 requires a published information security policy that is specific enough to mean something. 5.3 requires that roles, responsibilities, and authorities for information security be assigned and communicated clearly, so accountability does not default to whoever happens to be in the room when something breaks.
Why it is central
Clause 5 is the clause that gives clause 7.1’s resourcing requirement and clause 9.3’s management review their teeth. An ISMS whose leadership commitment is a signature on a policy document, with no visible follow-through, tends to show up downstream as chronic under-resourcing, management reviews nobody attends with real authority, and a security team pushing uphill on every decision.
The documents that come out of clause 5
- The information security policy, available as documented information, communicated internally, and available to interested parties as appropriate (5.2)
5.1 and 5.3 do not themselves mandate a standalone document, though most organizations record leadership commitment and a roles/responsibilities matrix as supporting evidence anyway.
Support
Need hands-on support turning leadership commitment into something auditable? See the ISO 27001 compliance service or go back to the 7-clause guide.
Sources
Frequently asked questions
- Who counts as top management for clause 5?
- The person or group who directs and controls the organization at the highest level — for a small company, the founder or CEO; for a larger one, a senior executive with real authority over resourcing and priorities. What matters to the auditor is that this person can actually decide on the ISMS budget, scope and priorities, not merely endorse them.
- Does the security policy need to be public?
- Not necessarily public, but it must be available as documented information, communicated within the organization and available to interested parties as appropriate. Many organizations publish a summary externally while keeping the full policy internal; the point is to decide deliberately what version, if any, is shared with customers or partners who ask for it.
- Which documents does clause 5 require?
- Only one document is explicitly required: the information security policy (5.2), available as documented information, communicated internally and available to interested parties as appropriate. 5.1 and 5.3 do not mandate a standalone document, but most organizations record leadership commitment and a roles-and-responsibilities matrix as supporting evidence anyway.
Related pages
ISO 27001 guide · Clause 5
5.1 — Leadership and commitment
ISO 27001:2022 sub-clause 5.1 requires top management to demonstrate leadership and commitment to the ISMS through eight specific, checkable actions.
ISO 27001 guide · Clause 5
5.2 — Information security policy
ISO 27001:2022 sub-clause 5.2 requires a published information security policy appropriate to your organization and committed to continual improvement.
ISO 27001 guide · Clause 5
5.3 — Organizational roles, responsibilities and authorities
ISO 27001:2022 sub-clause 5.3 requires security roles, responsibilities and authorities to be assigned, communicated and reported back to top management.
Let's talk about your compliance program.
Last updated: 2026-09-17
