Skip to main content
Informationssicherheit / NIS2

Management review

The management review is the assessment of the information security management system that ISO/IEC 27001 clause 9.3 requires top management to carry out at planned intervals in order to judge its continuing suitability, adequacy and effectiveness.

The management review is the formal occasion on which the top management of an organisation evaluates the information security management system (ISMS) as a whole. ISO/IEC 27001:2022 requires in clause 9.3.1 that this happens at planned intervals, and sets the yardstick: the continuing suitability, adequacy and effectiveness of the ISMS. Unlike the internal audit under clause 9.2, which checks whether individual processes conform to requirements, the management review is a governance decision. It is the point in the PDCA cycle at which leadership visibly takes ownership of the ISMS and decides on resources, objectives and course corrections. Preparing the review may be delegated, typically to the information security officer, but the evaluation itself and the resulting decisions may not. Documented information must be retained as evidence of the review.

Clause 9.3.2 prescribes the inputs that the review must consider: the status of actions from previous management reviews; changes in external and internal issues relevant to the ISMS; changes in the needs and expectations of interested parties; feedback on information security performance, including nonconformities and corrective actions, monitoring and measurement results, audit results and the fulfilment of information security objectives; feedback from interested parties; the results of risk assessment and the status of the risk treatment plan; and opportunities for continual improvement. Amendment ISO/IEC 27001:2022/Amd 1:2024 added the requirement to determine whether climate change is a relevant issue for the organisation; where it is, that assessment belongs in the context that leadership reviews. In practice it pays to mirror this list one to one in the agenda, because certification auditors use it to test completeness.

Under clause 9.3.3 the results must include decisions on opportunities for continual improvement and on any need for changes to the ISMS, so simply noting the reports is not enough. A defensible set of minutes therefore records concrete actions with owners, deadlines and budget, and links them to the improvement process of clause 10. The standard deliberately sets no fixed frequency; an annual cycle is customary and audit-proof, supplemented by ad hoc reviews after severe security incidents, mergers, major architectural changes or new regulatory requirements. The classic findings raised in certification audits are an incomplete list of inputs, minutes without traceable decisions, and a review that was effectively run by the security officer rather than by top management. The regulatory weight of the meeting is growing as well: under the management-body duties of the NIS2 Directive and its national transpositions, the management bodies of essential and important entities must approve the cyber risk management measures and oversee their implementation, and the management review is the natural documented place where that duty is discharged and evidenced.

Legal Basis

ISO/IEC 27001:2022 clause 9.3 (read with 9.1, 9.2 and 10.1), ISO/IEC 27001:2022/Amd 1:2024, guidance in ISO/IEC 27003; Art. 20 NIS2 Directive (EU) 2022/2555 and the corresponding management-body duties in the German NIS2 implementation act (BSIG as amended)

Practical Example

A mid-sized SaaS provider with around 180 employees has held ISO/IEC 27001 certification for two years and is preparing its annual management review for early March. Four weeks ahead, the information security officer assembles a briefing pack that follows the input list of clause 9.3.2 exactly: open actions from last year (seven of nine closed, two deferred); changed conditions arising from a new data centre provider and from the company's own NIS2 scoping assessment; customer requirements taken from two tender processes; last year's metrics (patch lead time, phishing click rate, time to incident report); 23 reported security incidents, two of them with data protection relevance; the internal audit results with three minor nonconformities; and the current risk treatment plan with four risks above the acceptance threshold. In a two-hour session the managing directors decide on that basis: budget for multi-factor authentication on all administrative access by Q3, an additional half position for vulnerability management, refusal to accept the residual risk of a legacy system together with a migration mandate by year end, and a tightened target for patch lead time. The minutes capture the decision, the owner and the deadline for each item, are signed off by the management, and serve in the surveillance audit as evidence for clause 9.3 as well as proof that leadership approved and oversaw the risk management measures.

FAQ

ISO/IEC 27001 sets no fixed interval; it only requires planned intervals. An annual cycle has become the norm because it dovetails neatly with internal audits, metrics and the certification cycle. In addition, ad hoc reviews are advisable after severe security incidents, acquisitions or new regulatory requirements. What matters for an audit is that the organisation defines its own interval, documents it and then actually keeps to it.
Accountability sits with top management, that is the managing directors or the board, who take the decisions and cannot delegate that responsibility. Preparing and consolidating the inputs is usually done by the information security officer, often together with IT management, the data protection officer and process owners. A review that is effectively run by the security officer and merely circulated to leadership afterwards regularly triggers a nonconformity in the certification audit.
The standard requires documented information as evidence of the results of the management review. Auditors typically check that every input listed in clause 9.3.2 was demonstrably covered, that the minutes contain concrete decisions on improvements and on changes to the ISMS, and that actions carry owners and deadlines. They also check whether actions from the previous review were followed up. A slide deck without recorded decisions is not sufficient evidence.

How preeco supports you

Learn how our software supports you with this topic.

Learn more