Why it matters
Auditors want proof that security isn't just a policy on paper — leadership actually acts on it.
How a self-led small team implements it
A short paragraph in onboarding materials plus visible participation in management review is usually sufficient evidence.
What auditors expect to see
Management review minutes, leadership communications referencing security.
Track A.5.4 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.
Start your ISMS