Clause 5 — Leadership
An ISMS that top management does not actively own is a documentation exercise, not a management system — and clause 5 is where the standard makes that ownership a certifiable requirement rather than a hope. It asks for demonstrated commitment from top management, not just sign-off; a published security policy that actually says something specific to your organization; and roles and authorities assigned clearly enough that when something goes wrong, everyone already knows whose job it is to respond. Auditors treat weak clause 5 evidence as a warning sign for the rest of the file, because a security program without genuine leadership backing rarely survives contact with competing business priorities.
The structure of clause 5
5.1 · Leadership and commitment
5.2 · Policy
5.3 · Organizational roles, responsibilities and authorities
What clause 5 covers
Clause 5 is flat — three requirements, no sub-clauses, like clauses 4, 8, and 10. 5.1 requires top management to actually demonstrate commitment to the ISMS, not just approve it once. 5.2 requires a published information security policy that is specific enough to mean something. 5.3 requires that roles, responsibilities, and authorities for information security be assigned and communicated clearly, so accountability does not default to whoever happens to be in the room when something breaks.
Why it is central
Clause 5 is the clause that gives clause 7.1’s resourcing requirement and clause 9.3’s management review their teeth. An ISMS whose leadership commitment is a signature on a policy document, with no visible follow-through, tends to show up downstream as chronic under-resourcing, management reviews nobody attends with real authority, and a security team pushing uphill on every decision.
The documents that come out of clause 5
- The information security policy, available as documented information, communicated internally, and available to interested parties as appropriate (5.2)
5.1 and 5.3 do not themselves mandate a standalone document, though most organizations record leadership commitment and a roles/responsibilities matrix as supporting evidence anyway.
Frequently asked questions
Who counts as "top management" for clause 5?
Does the security policy need to be public?
Need hands-on support turning leadership commitment into something auditable? See our ISO 27001 certification support service
Make leadership commitment visible, not just signed.
Sentrix helps you document leadership commitment, publish a real security policy, and assign roles that hold up at audit.