isms.coach
← All clauses

Clause 5

Leadership

Sub-clauses

  • 5.1 Leadership and commitment
  • 5.2 Policy
  • 5.3 Organizational roles, responsibilities and authorities

Why it matters

Auditors specifically check that security isn't just an IT project — someone senior has to visibly own it. A policy nobody in leadership can speak to without notes is a red flag.

What it requires

A documented, approved Information Security Policy; clearly assigned roles for who owns what; demonstrable evidence leadership actually participates (management review attendance, for instance, not just a signature).

How a self-led small team handles it

For a small company, "leadership" might just be you — that's fine. Write the policy in your own voice from your real context, not a generic template, and make sure whoever's accountable can actually explain it unprompted.

Track Clause 5 directly — itsbestpractice has a dedicated Policy section built around exactly this clause.

Start your ISMS