Leadership Commitment & Roles Matrix (Clause 5)
1. Management Commitment (Clause 5.1)
Executive leadership is committed to: * Integrating information security requirements into core business processes. * Ensuring necessary financial, technical, and human resources are allocated. * Directing and supporting individuals to contribute to the effectiveness of the ISMS. * Driving continuous improvement through regular management reviews.
2. Roles and Responsibilities (Clause 5.3)
| Role | Primary ISMS Responsibilities | Key Deliverables / Oversight |
|---|---|---|
| Executive Management / Board | Final approval of ISMS policies, risk appetite, and capital allocation. | Annual Management Review Sign-off |
| Lead Implementer / CISO | Day-to-day architecture, risk assessment facilitation, internal audits, and external auditor liaison. | ISMS Maintenance, SoA, Risk Register, Audit Reports |
| IT & Infrastructure Lead | Technical control implementation (firewalls, endpoint encryption, patching, log management). | Intune policies, patch compliance, vulnerability remediation |
| Department Leads (HR/Ops) | Enforcing onboarding/offboarding workflows, reporting anomalies, ensuring local compliance. | Leaver notifications, training completion tracking |
| All Staff & Contractors | Adherence to Acceptable Use, reporting suspicious emails or incidents, protecting credentials. | Mandatory training, clear desk adherence |