Sub-clauses
- 5.1 Leadership and commitment
- 5.2 Policy
- 5.3 Organizational roles, responsibilities and authorities
Why it matters
Auditors specifically check that security isn't just an IT project — someone senior has to visibly own it. A policy nobody in leadership can speak to without notes is a red flag.
What it requires
A documented, approved Information Security Policy; clearly assigned roles for who owns what; demonstrable evidence leadership actually participates (management review attendance, for instance, not just a signature).
How a self-led small team handles it
For a small company, "leadership" might just be you — that's fine. Write the policy in your own voice from your real context, not a generic template, and make sure whoever's accountable can actually explain it unprompted.
Track Clause 5 directly — itsbestpractice has a dedicated Policy section built around exactly this clause.
Start your ISMS