Step 6 · Audit and improvement
Management review Management decides what changes.
In the management review, top management checks whether the management system is still suitable, adequate and effective – and decides what needs to change.
What it is about
ISO/IEC 27001 clause 9.3 requires a review at planned intervals. Inputs include the status of previous decisions, changes in context, feedback on performance such as nonconformities, measurement results, audit results and the fulfilment of objectives, the results of risk assessment and opportunities for improvement. The output is decisions on improvements and needed changes. Under NIS2 this matches management’s duty to oversee implementation (Section 38 BSIG).
- Major 1
- Minor 4
- Observation (OFI) 6
Corrections closed · 9 / 11
Sample values
How to go about it
- 01
Set the date and participants; management attends.
- 02
Prepare the inputs: metrics, audit results, incidents, risks.
- 03
Decide: resources, objectives, changes.
- 04
Minute decisions with owners and deadlines.
Common mistakes
- A presentation without decisions.
- Management only takes note by email.
- Decisions are not followed up.
What an auditor wants to see
- Minutes covering all required inputs
- Decisions with owners and deadlines
- Evidence of implementation in the next cycle
How UniqSuite helps
The board report in UniqSuite summarises the security posture, the status per framework, open critical requirements and overdue deadlines in compact form – a good input for the management review.
References
- ISO/IEC 27001, clause 9.3
- ISO/IEC 27001, clause 10.1: continual improvement
- Section 38(1) BSIG
Frequently asked questions
How often does it take place?
At planned intervals, in practice at least once a year.
Is a monthly report enough?
It makes oversight easier but does not replace the formal review with decisions.
Is management liable?
Yes. If management breaches its duty to implement and oversee the measures, it is liable to the entity for culpably caused damage under company law (Section 38(2) BSIG). Minutes of the management review can show that oversight took place.
Does management have to be trained?
Yes. Under Section 38(3) BSIG it must take part in training regularly, so that it can identify and assess risks and risk management practices.
Does everything have to be covered in one meeting?
No, the standard does not prescribe a format. What matters is that all required inputs are covered within the cycle and the results are documented.
See what this looks like in UniqSuite.
In half an hour we walk you through it with your own questions.
