A Practical Guide for Startups
Management review is an important part of an ISO/IEC 27001 Information Security Management System (ISMS).
It provides top management with a structured opportunity to review whether the ISMS remains suitable, adequate, effective, and aligned with the organization’s business objectives and changing risks.
Management review should not be treated as a formal meeting held only before a certification audit.
The objective is to ensure that management understands:
- What information security risks the organization faces
- How effectively those risks are being managed
- Whether security objectives are being achieved
- Whether controls are working
- What has changed
- What problems remain
- What resources are required
- What improvements should be made
1. What Is an ISO 27001 Management Review?
A management review is a formal evaluation by top management of the organization’s ISMS.
It is different from an operational security meeting.
For example:
Operational Security Meeting
“We have three critical vulnerabilities. The IT team will fix them this week.”
Management Review
“Are our vulnerability-management objectives being achieved? Are critical vulnerabilities being addressed within the defined timeframe? Are additional resources or changes to the security program required?”
The management review focuses on the performance and direction of the ISMS, rather than managing individual technical tasks.
2. Why Is Management Review Important?
Management review helps ensure that information security remains a business responsibility.
It allows management to evaluate:
- ISMS performance
- Security risks
- Security objectives
- Audit findings
- Incidents
- Control effectiveness
- Resource requirements
- Changes affecting the organization
- Opportunities for improvement
It also provides evidence that top management is actively involved in the ISMS.
3. Who Should Participate?
The management review should involve appropriate members of top management and relevant ISMS stakeholders.
Depending on the size of the organization, participants may include:
- CEO
- Founder
- CTO
- CIO
- CISO
- Security Manager
- ISMS Manager
- Compliance Manager
- Risk Manager
- IT Manager
- Relevant business/process owners
For a small startup, the meeting may be relatively simple.
Example — 25-person SaaS startup
| Role | Contribution |
|---|---|
| CEO | Business direction and resource decisions |
| CTO | Technology and security risks |
| Security/ISMS Manager | ISMS performance and compliance |
| Engineering Lead | Application security |
| IT Lead | Infrastructure and access |
| HR | Personnel security |
| Operations | Supplier/business-process risks |
Not every function needs to attend every review. Participation should reflect the organization’s context and risks.
4. How Frequently Should Management Review Take Place?
Management review should occur at planned intervals.
The organization should define its own frequency based on its circumstances and risk.
Many organizations conduct management review:
- Annually
- Semi-annually
- Quarterly
A startup may choose:
Quarterly management review during the initial implementation period, followed by a defined periodic review once the ISMS is established.
Additional reviews may be appropriate following significant events such as:
- Major security incident
- Significant organizational change
- New regulatory requirement
- Major customer requirement
- Acquisition or merger
- Major technology change
- Significant change in ISMS scope
- Significant change in risk profile
The important point is that management review should be planned and performed at appropriate intervals.
5. Management Review Inputs
Management review should consider information that allows management to evaluate ISMS performance and determine whether changes or improvements are required.
A practical management review agenda can include the following areas.
5.1 Status of Previous Management Review Actions
Start by reviewing decisions and actions from the previous management review.
For each action:
- What was the action?
- Who owns it?
- What was the target date?
- Has it been completed?
- Is it overdue?
- Was the action effective?
Example
| Action | Owner | Due Date | Status |
|---|---|---|---|
| Implement MFA for all admin accounts | IT | 15 Aug | Completed |
| Review critical suppliers | Procurement | 30 Aug | Completed |
| Improve vulnerability SLA | CTO | 15 Sep | In progress |
The purpose is not simply to report status but to determine whether outstanding actions require management intervention.
6. Changes in Internal and External Issues
Management should consider changes that could affect the ISMS.
External changes
- New regulations
- New customer requirements
- Emerging cyber threats
- Industry changes
- New contractual requirements
- Changes in technology
- Supplier changes
Internal changes
- New employees
- Organizational restructuring
- New products
- New applications
- New cloud environments
- Changes to business processes
- New locations
- Changes in responsibilities
- Changes to ISMS scope
Example
A SaaS startup begins processing healthcare-related customer information.
Management should consider whether this changes:
- Risk assessment
- Legal requirements
- Customer requirements
- Security controls
- Data protection requirements
- Training requirements
- ISMS scope
7. Changes in Information Security Risks
Management should review the organization’s current risk position.
Useful information may include:
- New risks
- Closed risks
- High and critical risks
- Overdue treatment actions
- Residual risks
- Risk acceptance decisions
- Changes in risk ratings
- Emerging threats
Example
| Risk | Initial Risk | Residual Risk | Status |
|---|---|---|---|
| Privileged AWS access | Critical | Medium | Monitoring |
| Customer data exposure | Critical | Medium | Treatment ongoing |
| Supplier security incident | High | Medium | Accepted |
| Ransomware | High | Low | Controlled |
Management should determine whether residual risks remain acceptable under the organization’s defined criteria.
8. Information Security Objectives
Management should review progress against established information security objectives.
Example:
| Objective | Target | Current Result | Status |
|---|---|---|---|
| Critical vulnerability remediation | ≥95% within SLA | 97% | Achieved |
| Privileged access reviews | 100% quarterly | 100% | Achieved |
| Security training | 100% completion | 98% | Action required |
| Backup success | ≥99% | 99.7% | Achieved |
| Incident response | Within defined SLA | 94% | Improvement required |
Management should discuss:
- Whether objectives remain appropriate
- Whether targets are being achieved
- Reasons for missed targets
- Corrective actions
- New objectives required
9. Security Performance and Metrics
Management review should include relevant information security performance indicators.
Possible metrics include:
Vulnerability Management
- Number of critical vulnerabilities
- Average remediation time
- Overdue vulnerabilities
Access Management
- Privileged accounts
- Access-review completion
- Orphaned accounts
- Access exceptions
Incident Management
- Number of incidents
- Severity
- Response time
- Resolution time
- Repeat incidents
Security Awareness
- Training completion
- Phishing simulation results
- Incident reporting rate
Supplier Security
- Critical suppliers assessed
- Outstanding supplier issues
- Contract security reviews
Metrics should be selected based on what is meaningful to the organization’s security objectives and risks.
10. Internal Audit Results
Management should review the results of internal audits.
The review may include:
- Number of findings
- Major/nonconformity findings
- Minor/nonconformity findings
- Opportunities for improvement
- Recurring findings
- Overdue corrective actions
- Root causes
- Trends
Example
Previous period:
8 findings
Current period:
3 findings
Management should not automatically interpret fewer findings as proof that the ISMS is more effective.
The organization should consider:
- Audit scope
- Audit methodology
- Changes in risk
- Changes in organizational size
- Recurring issues
- Control effectiveness
11. Nonconformities and Corrective Actions
Management should review significant nonconformities and corrective actions.
For each significant issue, consider:
- What happened?
- What caused it?
- What correction was taken?
- What corrective action was implemented?
- Has the action been completed?
- Was effectiveness verified?
- Is the issue recurring?
Example
Finding: Former employee account remained active.
Root cause: HR-to-IT termination notification was manual.
Corrective action: Introduce automated employee termination notification and access-removal workflow.
Effectiveness check: Sample subsequent employee departures.
Management should focus on systemic issues rather than simply closing individual findings.
12. Security Incidents
Management should review significant information security incidents and lessons learned.
The review may include:
- Number of incidents
- Incident severity
- Root causes
- Response effectiveness
- Customer impact
- Regulatory impact
- Recovery performance
- Corrective actions
- Lessons learned
Example
A phishing incident resulted in compromise of an employee account.
Management may decide to:
- Increase MFA coverage
- Improve phishing awareness
- Strengthen email security
- Review conditional-acce
