Skip to content

Leadership Commitment & Roles Matrix (Clause 5)

1. Management Commitment (Clause 5.1)

Executive leadership is committed to: * Integrating information security requirements into core business processes. * Ensuring necessary financial, technical, and human resources are allocated. * Directing and supporting individuals to contribute to the effectiveness of the ISMS. * Driving continuous improvement through regular management reviews.


2. Roles and Responsibilities (Clause 5.3)

Role Primary ISMS Responsibilities Key Deliverables / Oversight
Executive Management / Board Final approval of ISMS policies, risk appetite, and capital allocation. Annual Management Review Sign-off
Lead Implementer / CISO Day-to-day architecture, risk assessment facilitation, internal audits, and external auditor liaison. ISMS Maintenance, SoA, Risk Register, Audit Reports
IT & Infrastructure Lead Technical control implementation (firewalls, endpoint encryption, patching, log management). Intune policies, patch compliance, vulnerability remediation
Department Leads (HR/Ops) Enforcing onboarding/offboarding workflows, reporting anomalies, ensuring local compliance. Leaver notifications, training completion tracking
All Staff & Contractors Adherence to Acceptable Use, reporting suspicious emails or incidents, protecting credentials. Mandatory training, clear desk adherence