Management Review

The management review is the regular evaluation of the management system by top management. ISO/IEC 27001 requires it in clause 9.3 at planned intervals: on the basis of defined inputs, management judges whether the ISMS is still suitable, adequate and effective. The outcome is not a set of minutes but a documented decision.

ISO 27001Last reviewed:

The management review is the occasion at which top management decides about the management system. ISO/IEC 27001 requires it in clause 9.3 at planned intervals and attaches a clear expectation: management evaluates whether the ISMS is still suitable, adequate and effective. What has to come out of it is a documented decision with owners, dates and, where needed, resources. Minutes recording a presentation are not that.

Inputs

The standard lists what has to be in front of management. That includes:

  • the status of actions from previous reviews,
  • changes in external and internal issues and in the requirements of interested parties,
  • feedback on the performance of the ISMS, in particular nonconformities and corrective actions, monitoring and measurement results, audit results and the extent to which security objectives have been met,
  • feedback from interested parties,
  • the results of the risk assessment and the state of the risk treatment plan,
  • opportunities for continual improvement.

The list is a minimum requirement for how well informed management has to be, not an agenda. Reproduce it one for one in slides and you produce a presentation; use it as a basis for decisions and it serves its purpose.

Outputs

What is required are decisions on opportunities for improvement and on the need to change the management system. Typically those are resolutions about the scope, about security objectives and metrics, about resources and roles, about how open nonconformities are to be handled, and about accepting or refusing risks above the acceptance threshold. Every one of those decisions belongs in the documented information with a date, an owner and a deadline.

Who takes part

Top management means the level that can approve resources and set priorities bindingly; in a mid-sized company, the managing directors. The information security officer or CISO prepares the material and presents it, but does not decide. A management review held without management does not meet the requirement, and auditors check this point reliably.

Interval and format

The standard says planned intervals, not a fixed cycle. An annual overall review is widespread, but on its own it creates a long window for reacting. A staged format has proved itself: a short steering session at shorter intervals for open nonconformities, metrics and risks, plus the full review with all required inputs once a year. What matters is that the chosen interval is defined, justified and kept to.

Metrics that can carry a decision

MetricWhat it showsPossible decision
Open nonconformities by agewhether corrective actions are being completedescalation, additional resources, revised deadlines
Share of overdue actions per areawhere implementation is stallingreprioritisation, change of ownership
Risks above the acceptance thresholdwhether the assumptions made still holdtreatment, or acceptance with a review date
Coverage of the audit programmewhether the relevant areas were actually examinedadjustment of the programme
Share of expired evidencewhether the evidence base is currentrenewal rhythm, automation
Incidents by category and recurrencewhether causes were genuinely removedrenewed root cause analysis

Metrics with no target value and no owner behind them produce no decision. The organisation sets the target values itself; there are no normative specifications for them.

Where the review falls short

  • The review took place, but without the required inputs.
  • Topics were discussed, but no decisions were taken.
  • Resolutions are documented, but with no owner and no deadline.
  • The review repeats the audit report instead of evaluating it.
  • Actions from the last review no longer appear in the next one.

Where the input for clause 9.3 comes from

The effort in a management review lies in the pack, not in the meeting. Clause 9.3 requires a fixed list of inputs, and in many organisations each comes from a different source: audit results from a report, nonconformities from a tracker, objectives from a spreadsheet, risk from a register.

In Rizzqo they come from one estate. Open requirements per object, nonconformities as open items with an owner, objective attainment as computed coverage and the risk picture as exposure in euros all sit against the same objects and cannot drift apart. A daily snapshot supplies the time axis, so leadership judges a development rather than a moment. The accountability question is answerable too, because every open requirement carries a named assignee.

Browse all entriesBack to top

Frequently asked questions

See compliance run on your real assets

Rizzqo turns framework requirements into owned tasks on the assets you already have, and prices the risk in real money.

Made in GermanyHosted in your countryMulti-framework