What is reviewed
ISO 27001 (clause 9.3) lists the inputs: the status of actions from previous reviews, changes in internal and external issues and in the needs of interested parties, results of monitoring and measurement, nonconformities and corrective actions, internal audit results, the achievement of security objectives, feedback from interested parties, results of the risk assessment and the status of the risk treatment plan, and opportunities for improvement.
What comes out of it
Decisions on improvements, changes to the ISMS, resources and priorities. These outputs must be recorded, usually as minutes with actions, owners and deadlines, and followed up at the next review.
Why it matters
It is the point where security becomes a leadership decision rather than a technical task. Auditors check that the review took place, that management actually attended, that all the required inputs were covered and that the decisions were followed through. A missing or superficial review is a common audit finding.
Making it useful
Keep it short and focused on decisions: a one page summary of incidents, risks, audit findings and progress against objectives, with clear requests for budget or priorities. Holding it shortly after the internal audit and before the certification audit is a common rhythm.




