GlossaryISO 27001

Management review

Short answer

A management review is a formal, scheduled meeting in which top management assesses whether the information security management system is still suitable, adequate and effective, and decides on changes and resources. ISO 27001 requires it at planned intervals, usually at least once a year.

What is reviewed

ISO 27001 (clause 9.3) lists the inputs: the status of actions from previous reviews, changes in internal and external issues and in the needs of interested parties, results of monitoring and measurement, nonconformities and corrective actions, internal audit results, the achievement of security objectives, feedback from interested parties, results of the risk assessment and the status of the risk treatment plan, and opportunities for improvement.

What comes out of it

Decisions on improvements, changes to the ISMS, resources and priorities. These outputs must be recorded, usually as minutes with actions, owners and deadlines, and followed up at the next review.

Why it matters

It is the point where security becomes a leadership decision rather than a technical task. Auditors check that the review took place, that management actually attended, that all the required inputs were covered and that the decisions were followed through. A missing or superficial review is a common audit finding.

Making it useful

Keep it short and focused on decisions: a one page summary of incidents, risks, audit findings and progress against objectives, with clear requests for budget or priorities. Holding it shortly after the internal audit and before the certification audit is a common rhythm.

Related terms

Keep reading on this topic

ISO 27001 information security management: scope, risk treatment, Annex A controls, internal audit and the certification audit process, explained.

Go to the topic hub