Management Review Meeting Pack
Supplies the agenda, inputs and minutes structure that satisfy Clause 9.3 without turning the review into a compliance ritual.
Available soon
- Format
- Word
- Size
- 58 KB
- Length
- 15 pages
- Version
- 1.0
- Updated
What's inside
- Purpose and audience
- The agenda
- The pre-read pack, with owners
- Keeping it a decision meeting
- The decisions to record
- Minutes template
- After the meeting
- Worked example — the first management review
- Related documents
- Adapting this template
- Framework references
- Definitions
Preview
The document from section 1, as you will receive it. Highlighted [[text]] is for you to replace; shaded guidance boxes are for you to delete before approval. The cover and document control pages are in the file.
Purpose and audience
This pack runs the management review of [[Organisation Name]]'s information security management system (ISMS): the meeting at which top management — [[e.g. Executive Committee]] — looks at how the ISMS is doing and decides what to change. It gives the standing agenda, the papers to prepare and who prepares them, the decisions the meeting must record, and a minutes template with an action log. It is written to satisfy clause 9.3 Management review of ISO/IEC 27001:2022, and to be worth the time of the people in the room.
It is for the ISMS manager, [[e.g. Head of Information Security]], who prepares and records the meeting; for the executive sponsor, [[e.g. Chief Operating Officer]], who usually chairs or sponsors it; and for top management, who decide. It is not a report to the board, although the board report and this review draw on the same figures.
Guidance — delete before approval
The certification body reads the minutes of this meeting at Stage 1 and Stage 2. It looks for three things: that every input was considered, that decisions were taken, and that the actions were followed up. A meeting that "noted" everything and decided nothing will pass the first test and fail the other two. Before the first certification, at least one management review must be complete (IS-06).
When it meets
When | Why |
|---|---|
At least every [[12]] months | The planned interval; set it in your ISMS and keep to it |
Before the first certification: after the first internal audit cycle, before Stage 1 | So that the audit results are an input, and the certification body sees a completed review (IS-06) |
[[Quarterly, in the certification year — optional]] | A shorter review of readiness, actions and risks while the ISMS is new |
After a major incident, a major nonconformity, or a significant change to the organisation or the ISMS scope | An extra review, on the inputs affected |
Who attends
Attendee | Why they are there |
|---|---|
Top management [[e.g. Executive Committee]] | They decide: resources, changes to scope, policy and objectives, risks accepted. The review is theirs, not the security team's (clause 5.1). |
Executive sponsor [[e.g. Chief Operating Officer]] | Chairs, or sponsors the item list; follows up the actions between reviews. |
ISMS manager [[e.g. Head of Information Security]] | Prepares the pre-read, presents the decisions sought, records the minutes. |
Control owners [[the managers who run each control]] | Attend for the items they own, where a decision affects their area. |
Internal auditor [[independent of the area audited; internal or contracted]] | Optional: attends for the audit results item to answer questions on findings. |
The meeting is quorate when [[at least n members of top management, including the chair]] are present. Delegation to deputies is recorded in the minutes; a review attended only by the security team is not a management review.
The agenda
The standing agenda covers every input the standard asks a management review to consider (clause 9.3.2 Management review inputs), in our words, and ends with the decisions the review must produce (clause 9.3.3 Management review results). Keep the order: what was agreed last time, what has changed, how it is going, where the risks are, and what to do about it.
Item | Input | Looks back on | Decision sought |
|---|---|---|---|
0 | Opening: attendance, quorum, approval of the last minutes | — | Minutes approved |
1 | MR-1 What happened to the actions agreed at earlier reviews | — | Close, carry forward or re-plan each open action |
2 | MR-2 What has changed inside and outside the organisation that affects the ISMS | 4.1 Understanding the organization and its context | Does any change need a change to the ISMS (scope, policy, objectives)? |
3 | MR-3 What has changed in what interested parties need and expect from us | 4.2 Understanding the needs and expectations of interested parties | Does any new requirement need a change to the ISMS? |
4 | MR-4 How information security is performing, shown as trends: nonconformities and corrective actions; monitoring and measurement results; audit results; progress on the security objectives | 10.2 Nonconformity and corrective action; 9.1 Monitoring, measurement, analysis and evaluation; 9.2 Internal audit; 6.2 Information security objectives and planning to achieve them | Are the trends acceptable? Which need action? |
5 | MR-5 What interested parties are telling us: customers, regulators, staff, suppliers | 4.2 Understanding the needs and expectations of interested parties | Does any feedback need a response or a change? |
6 | MR-6 Where the risks stand: the latest risk assessment results and how the risk treatment plan is progressing | 8.2 Information security risk assessment; 8.3 Information security risk treatment | Accept the residual risks put forward, or send them back; is treatment on track? |
7 | MR-7 Where we could improve | 10.1 Continual improvement | Take up or decline each opportunity |
8 | Conclusions and decisions (MD-1 to MD-7) | 9.3.3 Management review results; 5.1 Leadership and commitment | The results of the review, recorded |
9 | Actions read back; date of the next review | — | Owners and dates confirmed |
Guidance — delete before approval
Allow [[90 to 120]] minutes. Spend most of it on MR-4, MR-6 and item 8. The first item, MR-1, should take five minutes: the action log is in the pre-read.
In a certification year, add a readiness item under MR-4 using the pack's headline measures (see the pre-read table). It is not an input the standard names, but it is the question the meeting will ask.
The pre-read pack, with owners
Each input owner sends a short paper — [[one or two pages]], trends not snapshots — to the ISMS manager at least [[10]] working days before the meeting. The ISMS manager assembles the pre-read, adds a one-page summary of the decisions sought, and issues it at least [[5]] working days before. Where a CISO Times document already produces the figures, use it rather than building a new report.
Input | What to bring | Where it comes from | Owner |
|---|---|---|---|
MR-1 | The action log from the last review: each action with owner, due date, status, and the evidence for any closed. | The minutes and action log of the last review (this pack). First review: none — record that it is the first. | ISMS manager |
MR-2 | Changes since the last review: organisation, services, technology, suppliers, threats, law. One line each, with its effect on the ISMS. | [[Your context record (clause 4.1)]]; Board Cybersecurity Report Deck Template (Board Cybersecurity Reporting pack); Third-Party Risk Dashboard (Third-Party Security Risk Management pack) for supplier changes | ISMS manager, with executive sponsor |
MR-3 | New or changed requirements from customers, regulators, insurers, staff and suppliers, including contract terms. | [[Your interested parties record (clause 4.2)]]; [[legal or compliance]] | [[Legal or compliance]] |
MR-4 nonconformities | Nonconformities and corrective actions: opened, closed, overdue, repeat; effectiveness checks passed. | ISMS Internal Audit Programme & Procedure (finding records); ISMS Gap & Remediation Tracker | ISMS manager |
MR-4 measurement | Monitoring and measurement results against targets, as trends over the last [[four]] periods. | Policy Health & Attestation Reporting Workbook (Security Policy Management pack); Risk Reporting Dashboard (Information Security Risk Management pack); Third-Party Risk Dashboard (Third-Party Security Risk Management pack); Access Review Outcome Report Template (User Access Review pack); Board Cybersecurity Report Deck Template (Board Cybersecurity Reporting pack) or Cyber Risk One-Page Board Summary (Board Cybersecurity Reporting pack); [[incident log]] | ISMS manager; measure owners |
MR-4 audit results | The programme summary: audits done against plan, findings by grade and area, the auditors' view of the weakest areas. | ISMS Internal Audit Programme & Procedure (programme summary) | ISMS manager |
MR-4 objectives | Each security objective: target, current position, on track or not, and why. | [[Your security objectives record (clause 6.2)]] | Objective owners |
MR-4 readiness (certification year) | ISM-01 Blocking items operating; ISM-02 Requirements operating; ISM-03 Gaps overdue; ISM-04 Weeks to certification. | Certification Readiness Self-Assessment; ISMS Gap & Remediation Tracker | ISMS manager |
MR-5 | Complaints, customer questionnaires and audits, regulator contact, staff suggestions, supplier notices — what they said and what was done. | [[Customer and regulator correspondence]]; Third-Party Risk Dashboard (Third-Party Security Risk Management pack) | [[Account management; legal; HR]] |
MR-6 | The latest risk assessment: top risks and their movement, risks outside appetite, treatment plan progress, residual risks put forward for acceptance. | Risk Reporting Dashboard (Information Security Risk Management pack); Risk Treatment Plan (Information Security Risk Management pack) | [[Risk owners, through the ISMS manager]] |
MR-7 | Improvement proposals, each with cost and expected effect, including audit observations and ideas from any input above. | Observations in the ISMS Internal Audit Programme & Procedure; any input above | ISMS manager |
Guidance — delete before approval
A document marked "(coming)" is not yet published by CISO Times; use your own report for that input until it is.
Ask every owner for the same shape: the figure, its trend, what it means, and the decision they want. A paper with no decision sought is information; it belongs in the appendix.
Keeping it a decision meeting
A management review turns into a ritual when it is a presentation of the pre-read to people who have not read it. These habits keep it a meeting that decides:
- The pre-read is read. The chair opens by asking whether it has been; nobody presents slides that repeat it. Each item starts with the decision sought.
- Every item ends in a decision. 'No change' is a decision; record it as one, with the reason. 'Noted' is not.
- Trends, not snapshots. One figure tells the meeting nothing; four periods show whether anything is working.
- Bad news first. Overdue actions, repeat findings and risks outside appetite are taken before anything that went well.
- Options with costs. A request for resources comes with what it buys, what it costs, and what happens if it is refused (MD-4).
- The right people. The people who can commit resources and change priorities are in the room. If they send deputies, the minutes say so.
- Ask one hard question. 'What would we do differently if we started the ISMS again today?' — asked every time, answered honestly.
- Actions leave the room with an owner and a date, and are read back at the end.
Guidance — delete before approval
If the minutes of two reviews in a row could be swapped without anyone noticing, the review has become a ritual. Change the format before the certification body points it out.
The decisions to record
The results of the review (clause 9.3.3 Management review results) are its decisions. Record each one, even where the decision is to change nothing. Top management's part in them is what clause 5.1 Leadership and commitment asks to see.
Ref | Decision | Answers to |
|---|---|---|
MD-1 | Conclusion: does the ISMS still fit the organisation, is it enough, and does it work? One sentence each, with the reason. | 9.3.1 General; 5.1 Leadership and commitment |
MD-2 | Improvement opportunities: each one taken up (owner, date) or declined (reason). | 9.3.3 Management review results; 10.1 Continual improvement |
MD-3 | Changes needed to the ISMS: scope, policy, objectives, risk criteria, controls or processes — what changes, who changes it, by when. | 9.3.3 Management review results; 6.3 Planning of changes |
MD-4 | Resources: people, money and time agreed or refused, with the consequence of a refusal stated. | 5.1 Leadership and commitment; 7.1 Resources |
MD-5 | Risks: residual risks the risk owners ask management to accept, accepted or sent back for treatment. | 6.1.3 Information security risk treatment |
MD-6 | In a certification year: go ahead with, or move, the next certification audit. | 9.3.3 Management review results |
MD-7 | The date of the next review. | 9.3.1 General |
The minutes are the record the standard requires for clause 9.3.3 Management review results, and one of the 8 blocking items in the Certification Readiness Self-Assessment: without a completed review, a Stage 2 audit cannot pass.
Minutes template
Field | Content |
|---|---|
Meeting | [[ISMS management review]] — [[first / regular / extra]] |
Date, time and place | [[YYYY-MM-DD, hh:mm–hh:mm, room or call]] |
Chair | [[Name, role]] |
Present | [[Names and roles]] |
Apologies and deputies | [[Names; who deputised with what authority]] |
Quorum | [[Met / not met]] |
Pre-read issued | [[YYYY-MM-DD; list of papers]] |
For each agenda item:
Item | What the meeting considered | Discussion — key points only | Decision | Actions |
|---|---|---|---|---|
[[MR-n]] | [[The input, in one or two lines, with the paper's reference]] | [[Challenges, disagreements, questions]] | [[What was decided; or 'no change', with the reason]] | [[A-nn]] |
Conclusions and decisions (item 8):
Ref | Decision recorded |
|---|---|
MD-1 | [[Conclusion: …]] |
MD-2 | [[Improvement opportunities: …]] |
MD-3 | [[Changes needed to the ISMS: …]] |
MD-4 | [[Resources: …]] |
MD-5 | [[Risks: …]] |
MD-6 | [[In a certification year: …]] |
MD-7 | [[The date of the next review: …]] |
Action log
One log across reviews, carried forward until every action is closed. It is the first paper of the next review (MR-1).
Ref | Action | From item | Owner | Due | Status | Evidence of closure |
|---|---|---|---|---|---|---|
[[A-nn]] | [[What will be done]] | [[MR-n / MD-n]] | [[Role]] | [[YYYY-MM-DD]] | [[Open / Closed / Overdue / Re-planned]] | [[Reference]] |
After the meeting
When | What | Who |
|---|---|---|
Within [[3]] working days | Issue the minutes and the action log to the attendees; the chair confirms them. | ISMS manager |
With the minutes | Enter every action in the ISMS Gap & Remediation Tracker (or your own log), so that it is tracked with the other ISMS gaps. | ISMS manager |
With the minutes | Tell each action owner who was not present what they own and by when. | ISMS manager |
Within [[10]] working days | Update the documents the decisions changed: scope, policy, objectives, Statement of Applicability, risk acceptance records, audit programme. | Document owners |
Monthly | Review action progress in the monthly readiness review (IS-10) or the ISMS meeting; escalate an overdue action to the executive sponsor. | ISMS manager |
Before the next review | Close or re-plan every action; the log is MR-1. | ISMS manager |
A short follow-up note to an action owner:
Field | Content |
|---|---|
To | [[Action owner]] |
From | [[Name]], ISMS manager |
Review and item | [[Management review of YYYY-MM-DD, item MR-n]] |
Decision | [[The decision, as minuted]] |
Your action | [[A-nn: what, by when]] |
Evidence needed to close | [[What will show it is done]] |
Worked example — the first management review
EXAMPLE, not part of the template. The organisation is the one used throughout the pack: a software services company with 240 staff in two offices, an NIS2 important entity. Its first internal audit cycle (IA-01, IA-02, IA-03, IA-04, IA-05, IA-06) ran from 4 Nov 2026 to 9 Dec 2026, with the programme summary issued on 23 Dec 2026 (ISMS Internal Audit Programme & Procedure). The review falls 12 calendar days before Stage 1 (18 Jan 2027) and about 8 weeks before Stage 2 (1 Mar 2027). Audit IA-07, on 12 Jan 2027, audits this review. Replace every date, name and figure with your own.
Timetable
Date | Step |
|---|---|
23 Dec 2026 | Programme summary from the internal audit (EXAMPLE) |
23 Dec 2026 | Input papers to the ISMS manager (10 working days before) (EXAMPLE) |
30 Dec 2026 | Pre-read issued (5 working days before) (EXAMPLE) |
Wed, 6 Jan 2027, [[10:00–12:00]] | Management review (EXAMPLE) |
11 Jan 2027 | Minutes and action log issued (3 working days after) (EXAMPLE) |
12 Jan 2027 | IA-07 audits the review and the corrective action progress (EXAMPLE) |
18 Jan 2027 | Stage 1 |
Guidance — delete before approval
The input papers fall due over the year-end holidays in this example. Ask for them before the break, or move the review later — but not so late that the minutes are not ready for IA-07 and for Stage 1.
Agenda — completed
Item | Lead | Paper | Decision sought |
|---|---|---|---|
0 Opening | [[Chief Executive]] (chair) | — | First management review: no earlier minutes (EXAMPLE) |
MR-1 Earlier actions | ISMS manager | — | None: first review. Record that it is the first (EXAMPLE) |
MR-2 Changes | Executive sponsor | [[Context record]] | Any change since the scope was approved that affects it? [[e.g. a new product, a new hosting region]] (EXAMPLE) |
MR-3 Interested parties | [[Legal or compliance]] | [[Interested parties record]] | [[e.g. new customer contract security terms]]: change needed? (EXAMPLE) |
MR-4 Performance | ISMS manager | ISMS Internal Audit Programme & Procedure programme summary; Policy Health & Attestation Reporting Workbook (Security Policy Management pack); Certification Readiness Self-Assessment | Audit results: 6 audits done as planned; 0 major, 15 minor (F-01, F-02, F-03, F-04, F-05, F-06, F-07, F-08, F-09, F-10, F-11, F-12, F-13, F-14, F-15), 1 observation (O-01). Readiness: ISM-01 [[n]] of 8 blocking items operating. Is Stage 1 on? (EXAMPLE) |
MR-5 Feedback | [[Account management]] | [[Customer questionnaires received]] | [[Any response or change?]] (EXAMPLE) |
MR-6 Risks | [[Risk owners]] | Risk Reporting Dashboard (Information Security Risk Management pack); Risk Treatment Plan (Information Security Risk Management pack) | [[Accept the residual risks put forward?]] Treatment on track? (EXAMPLE) |
MR-7 Improvement | ISMS manager | O-01 and other observations | Take up O-01? (EXAMPLE) |
8 Decisions | Chair | Summary of decisions sought | MD-1 to MD-7 (EXAMPLE) |
9 Close | Chair | Action log | Next review date (EXAMPLE) |
Minutes — skeleton
Field | Content |
|---|---|
Meeting | ISMS management review — first (EXAMPLE) |
Date, time and place | 6 Jan 2027, [[10:00–12:00]], [[room]] (EXAMPLE) |
Chair | [[Chief Executive]] |
Present | [[Chief Executive]]; Chief Operating Officer (executive sponsor); Head of Information Security (ISMS manager); Head of IT; HR Director; Head of Procurement; [[Chief Financial Officer]] (EXAMPLE) |
Pre-read issued | 30 Dec 2026 (EXAMPLE) |
Item | Considered | Decision | Actions |
|---|---|---|---|
MR-1 | First review; no earlier actions. | No earlier actions (EXAMPLE) | — |
MR-4 audit results | 6 audits, covering every clause from 4 to 10 except 9.3, and every Annex A theme: 0 major and 15 minor nonconformities, raised wherever a requirement was not yet in place. 12 corrected by the review, including F-01 (the policy register: AUP-001, BKP-001 past review, corrected 18 Nov 2026); open: F-03, F-04, F-15. O-01: acknowledgement coverage 94.5% against a 95% target. | Corrective action plans accepted; the executive sponsor to see every open one corrected before Stage 2 (EXAMPLE) | [[A-01]] |
MR-4 measurement | PM-01 Documents past review date and PM-03 Acknowledgement coverage from the policy health workbook; [[other measures]]. | [[Decision]] (EXAMPLE) | [[A-nn]] |
MR-6 | [[Top risks and movement]]; the Supplier Security Policy (P04 register SUP-001) [[approved on YYYY-MM-DD / still awaiting approval]]. | [[Residual risks accepted or sent back]] (EXAMPLE) | [[A-nn]] |
MR-7 | O-01: re-acknowledgement after the reviewed Acceptable Use Policy is re-issued. | Taken up; owner HR Director (EXAMPLE) | [[A-02]] |
Ref | Decision recorded — EXAMPLE |
|---|---|
MD-1 | [[The ISMS fits the organisation and its scope; it is enough for the risks assessed; it works, with the nonconformities from the internal audit being corrected.]] (EXAMPLE) |
MD-2 | O-01 taken up (A-02). [[Other opportunities: taken up or declined, with reasons.]] (EXAMPLE) |
MD-3 | Supplier controls (A.5.19 to A.5.23) audited every year until the Supplier Security Policy (P04 register SUP-001) has operated for a year; the audit programme updated (ISMS Internal Audit Programme & Procedure, step 22). (EXAMPLE) |
MD-4 | [[e.g. Contracted auditor retained for the Year 2 audits of clauses 4 to 10.]] (EXAMPLE) |
MD-5 | [[Residual risks accepted, by reference; or none put forward.]] (EXAMPLE) |
MD-6 | Stage 1 goes ahead on 18 Jan 2027: the first audit cycle is complete and no major nonconformity is open. 12 of the 15 minor nonconformities are corrected; the other 3 (F-03, F-04, F-15) are in corrective action, the last due to be corrected by 3 Feb 2027, before Stage 2. (EXAMPLE) |
MD-7 | Next review: [[YYYY-MM]], no later than 12 months after this one. (EXAMPLE) |
Related documents
Document | Relationship |
|---|---|
ISO 27001 Implementation Methodology & Project Plan | The project plan: the first review closes Phase 5 (Check), before Stage 1 |
Certification Readiness Self-Assessment | Readiness and the headline measures ISM-01, ISM-02, ISM-03, ISM-04; clause 9.3.3 is a blocking item |
ISMS Gap & Remediation Tracker | Where the review's actions are tracked with the other ISMS gaps |
ISMS Internal Audit Programme & Procedure | The audit results and nonconformities (MR-4, MR-7); audits this review |
Stage 1 and Stage 2 Audit Preparation Guide | What the certification body will ask about the review at Stage 1 and Stage 2 |
Board Cybersecurity Report Deck Template; Cyber Risk One-Page Board Summary | The board's view of the same risks (MR-2, MR-4); Board Cybersecurity Reporting pack |
Risk Reporting Dashboard; Risk Treatment Plan | Risk assessment results and treatment progress (MR-6); Information Security Risk Management pack |
Third-Party Risk Dashboard | Supplier changes, performance and feedback (MR-2, MR-4, MR-5); Third-Party Security Risk Management pack |
Access Review Outcome Report Template | Access review results (MR-4); User Access Review pack |
Policy Health & Attestation Reporting Workbook | Policy currency and acknowledgement measures (MR-4); Security Policy Management pack |
Adapting this template
Guidance — delete before approval
Small organisation: top management may be two or three directors. Hold the review as an item of an existing management meeting, with its own minutes, and keep the agenda: the inputs can be one page each and the whole review [[60]] minutes. The decisions still have to be recorded one by one.
Regulated entity: ISO/IEC 27001:2022 is the requirement this pack meets. If you are also subject to NIS2 or DORA, the management body has its own duties to approve and oversee security risk management; this review can feed that oversight, and its minutes are good evidence of it — but a certificate is evidence, not compliance. Agree with [[legal or compliance]] whether the review should report to the board or a board committee, and add any regulatory reporting as an MR-3 item.
IT run by a service provider: ask the provider for its measures, incidents and changes in time for the input papers, and invite its account manager for the MR-4 and MR-5 items where useful. The decisions stay with your management.
Delete this section before approval.
Framework references
These references show where this document supports an external framework. They indicate relevance only and do not reproduce the text of any standard. Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0.
Framework | Reference | Supported by |
|---|---|---|
ISO/IEC 27001:2022 | Clause 9.3 — Management review | Whole pack |
ISO/IEC 27001:2022 | Clause 9.3.1 — General | When it meets; who attends; keeping it a decision meeting |
ISO/IEC 27001:2022 | Clause 9.3.2 — Management review inputs | The agenda (MR-1 to MR-7); the pre-read pack |
ISO/IEC 27001:2022 | Clause 9.3.3 — Management review results | The decisions to record (MD-1 to MD-7); minutes template; action log |
ISO/IEC 27001:2022 | Clause 5.1 — Leadership and commitment | Who attends; decisions on resources and direction (MD-1, MD-4) |
NIST CSF 2.0 | GV.OV-01 — “Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction” | The agenda and decisions: outcomes reviewed to adjust direction |
NIST CSF 2.0 | GV.RR-01 — “Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving” | Who attends; keeping it a decision meeting: leadership accountable |
Definitions
Term | Meaning in this pack |
|---|---|
Action log | The list of actions agreed at management reviews, each with an owner, a due date and a status, carried forward until closed. |
Input | A topic the review must consider (MR-1 to MR-7). |
Interested party | A person or organisation that can affect, or is affected by, the ISMS: customers, regulators, staff, suppliers, owners. |
ISMS | Information security management system: the policies, processes, people and records an organisation uses to manage information security risk. |
Management review | The planned meeting at which top management reviews the ISMS and decides what to change. |
Nonconformity | A requirement not met — of the standard, or of the organisation's own ISMS documents. |
Pre-read | The papers issued before the meeting, so that the meeting can decide rather than be informed. |
Quorum | The minimum attendance for the review's decisions to stand. |
Residual risk | The risk that remains after treatment; its acceptance is recorded (MD-5). |
Stage 1 and Stage 2 | The certification body's two audits: first of readiness and documentation, then of the ISMS in operation. |
Top management | The people who direct and control the organisation at the highest level: [[e.g. Executive Committee]]. |