Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Management Review Meeting Pack

Supplies the agenda, inputs and minutes structure that satisfy Clause 9.3 without turning the review into a compliance ritual.

Available soon

Format
Word
Size
58 KB
Length
15 pages
Version
1.0
Updated

What's inside

  • Purpose and audience
  • The agenda
  • The pre-read pack, with owners
  • Keeping it a decision meeting
  • The decisions to record
  • Minutes template
  • After the meeting
  • Worked example — the first management review
  • Related documents
  • Adapting this template
  • Framework references
  • Definitions

Preview

The document from section 1, as you will receive it. Highlighted [[text]] is for you to replace; shaded guidance boxes are for you to delete before approval. The cover and document control pages are in the file.

Purpose and audience

This pack runs the management review of [[Organisation Name]]'s information security management system (ISMS): the meeting at which top management — [[e.g. Executive Committee]] — looks at how the ISMS is doing and decides what to change. It gives the standing agenda, the papers to prepare and who prepares them, the decisions the meeting must record, and a minutes template with an action log. It is written to satisfy clause 9.3 Management review of ISO/IEC 27001:2022, and to be worth the time of the people in the room.

It is for the ISMS manager, [[e.g. Head of Information Security]], who prepares and records the meeting; for the executive sponsor, [[e.g. Chief Operating Officer]], who usually chairs or sponsors it; and for top management, who decide. It is not a report to the board, although the board report and this review draw on the same figures.

Guidance — delete before approval

The certification body reads the minutes of this meeting at Stage 1 and Stage 2. It looks for three things: that every input was considered, that decisions were taken, and that the actions were followed up. A meeting that "noted" everything and decided nothing will pass the first test and fail the other two. Before the first certification, at least one management review must be complete (IS-06).

When it meets

When

Why

At least every [[12]] months

The planned interval; set it in your ISMS and keep to it

Before the first certification: after the first internal audit cycle, before Stage 1

So that the audit results are an input, and the certification body sees a completed review (IS-06)

[[Quarterly, in the certification year — optional]]

A shorter review of readiness, actions and risks while the ISMS is new

After a major incident, a major nonconformity, or a significant change to the organisation or the ISMS scope

An extra review, on the inputs affected

Who attends

Attendee

Why they are there

Top management

[[e.g. Executive Committee]]

They decide: resources, changes to scope, policy and objectives, risks accepted. The review is theirs, not the security team's (clause 5.1).

Executive sponsor

[[e.g. Chief Operating Officer]]

Chairs, or sponsors the item list; follows up the actions between reviews.

ISMS manager

[[e.g. Head of Information Security]]

Prepares the pre-read, presents the decisions sought, records the minutes.

Control owners

[[the managers who run each control]]

Attend for the items they own, where a decision affects their area.

Internal auditor

[[independent of the area audited; internal or contracted]]

Optional: attends for the audit results item to answer questions on findings.

The meeting is quorate when [[at least n members of top management, including the chair]] are present. Delegation to deputies is recorded in the minutes; a review attended only by the security team is not a management review.

The agenda

The standing agenda covers every input the standard asks a management review to consider (clause 9.3.2 Management review inputs), in our words, and ends with the decisions the review must produce (clause 9.3.3 Management review results). Keep the order: what was agreed last time, what has changed, how it is going, where the risks are, and what to do about it.

Item

Input

Looks back on

Decision sought

0

Opening: attendance, quorum, approval of the last minutes

—

Minutes approved

1

MR-1 What happened to the actions agreed at earlier reviews

—

Close, carry forward or re-plan each open action

2

MR-2 What has changed inside and outside the organisation that affects the ISMS

4.1 Understanding the organization and its context

Does any change need a change to the ISMS (scope, policy, objectives)?

3

MR-3 What has changed in what interested parties need and expect from us

4.2 Understanding the needs and expectations of interested parties

Does any new requirement need a change to the ISMS?

4

MR-4 How information security is performing, shown as trends: nonconformities and corrective actions; monitoring and measurement results; audit results; progress on the security objectives

10.2 Nonconformity and corrective action; 9.1 Monitoring, measurement, analysis and evaluation; 9.2 Internal audit; 6.2 Information security objectives and planning to achieve them

Are the trends acceptable? Which need action?

5

MR-5 What interested parties are telling us: customers, regulators, staff, suppliers

4.2 Understanding the needs and expectations of interested parties

Does any feedback need a response or a change?

6

MR-6 Where the risks stand: the latest risk assessment results and how the risk treatment plan is progressing

8.2 Information security risk assessment; 8.3 Information security risk treatment

Accept the residual risks put forward, or send them back; is treatment on track?

7

MR-7 Where we could improve

10.1 Continual improvement

Take up or decline each opportunity

8

Conclusions and decisions (MD-1 to MD-7)

9.3.3 Management review results; 5.1 Leadership and commitment

The results of the review, recorded

9

Actions read back; date of the next review

—

Owners and dates confirmed

Guidance — delete before approval

Allow [[90 to 120]] minutes. Spend most of it on MR-4, MR-6 and item 8. The first item, MR-1, should take five minutes: the action log is in the pre-read.

In a certification year, add a readiness item under MR-4 using the pack's headline measures (see the pre-read table). It is not an input the standard names, but it is the question the meeting will ask.

The pre-read pack, with owners

Each input owner sends a short paper — [[one or two pages]], trends not snapshots — to the ISMS manager at least [[10]] working days before the meeting. The ISMS manager assembles the pre-read, adds a one-page summary of the decisions sought, and issues it at least [[5]] working days before. Where a CISO Times document already produces the figures, use it rather than building a new report.

Input

What to bring

Where it comes from

Owner

MR-1

The action log from the last review: each action with owner, due date, status, and the evidence for any closed.

The minutes and action log of the last review (this pack). First review: none — record that it is the first.

ISMS manager

MR-2

Changes since the last review: organisation, services, technology, suppliers, threats, law. One line each, with its effect on the ISMS.

[[Your context record (clause 4.1)]]; Board Cybersecurity Report Deck Template (Board Cybersecurity Reporting pack); Third-Party Risk Dashboard (Third-Party Security Risk Management pack) for supplier changes

ISMS manager, with executive sponsor

MR-3

New or changed requirements from customers, regulators, insurers, staff and suppliers, including contract terms.

[[Your interested parties record (clause 4.2)]]; [[legal or compliance]]

[[Legal or compliance]]

MR-4 nonconformities

Nonconformities and corrective actions: opened, closed, overdue, repeat; effectiveness checks passed.

ISMS Internal Audit Programme & Procedure (finding records); ISMS Gap & Remediation Tracker

ISMS manager

MR-4 measurement

Monitoring and measurement results against targets, as trends over the last [[four]] periods.

Policy Health & Attestation Reporting Workbook (Security Policy Management pack); Risk Reporting Dashboard (Information Security Risk Management pack); Third-Party Risk Dashboard (Third-Party Security Risk Management pack); Access Review Outcome Report Template (User Access Review pack); Board Cybersecurity Report Deck Template (Board Cybersecurity Reporting pack) or Cyber Risk One-Page Board Summary (Board Cybersecurity Reporting pack); [[incident log]]

ISMS manager; measure owners

MR-4 audit results

The programme summary: audits done against plan, findings by grade and area, the auditors' view of the weakest areas.

ISMS Internal Audit Programme & Procedure (programme summary)

ISMS manager

MR-4 objectives

Each security objective: target, current position, on track or not, and why.

[[Your security objectives record (clause 6.2)]]

Objective owners

MR-4 readiness (certification year)

ISM-01 Blocking items operating; ISM-02 Requirements operating; ISM-03 Gaps overdue; ISM-04 Weeks to certification.

Certification Readiness Self-Assessment; ISMS Gap & Remediation Tracker

ISMS manager

MR-5

Complaints, customer questionnaires and audits, regulator contact, staff suggestions, supplier notices — what they said and what was done.

[[Customer and regulator correspondence]]; Third-Party Risk Dashboard (Third-Party Security Risk Management pack)

[[Account management; legal; HR]]

MR-6

The latest risk assessment: top risks and their movement, risks outside appetite, treatment plan progress, residual risks put forward for acceptance.

Risk Reporting Dashboard (Information Security Risk Management pack); Risk Treatment Plan (Information Security Risk Management pack)

[[Risk owners, through the ISMS manager]]

MR-7

Improvement proposals, each with cost and expected effect, including audit observations and ideas from any input above.

Observations in the ISMS Internal Audit Programme & Procedure; any input above

ISMS manager

Guidance — delete before approval

A document marked "(coming)" is not yet published by CISO Times; use your own report for that input until it is.

Ask every owner for the same shape: the figure, its trend, what it means, and the decision they want. A paper with no decision sought is information; it belongs in the appendix.

Keeping it a decision meeting

A management review turns into a ritual when it is a presentation of the pre-read to people who have not read it. These habits keep it a meeting that decides:

  1. The pre-read is read. The chair opens by asking whether it has been; nobody presents slides that repeat it. Each item starts with the decision sought.
  2. Every item ends in a decision. 'No change' is a decision; record it as one, with the reason. 'Noted' is not.
  3. Trends, not snapshots. One figure tells the meeting nothing; four periods show whether anything is working.
  4. Bad news first. Overdue actions, repeat findings and risks outside appetite are taken before anything that went well.
  5. Options with costs. A request for resources comes with what it buys, what it costs, and what happens if it is refused (MD-4).
  6. The right people. The people who can commit resources and change priorities are in the room. If they send deputies, the minutes say so.
  7. Ask one hard question. 'What would we do differently if we started the ISMS again today?' — asked every time, answered honestly.
  8. Actions leave the room with an owner and a date, and are read back at the end.

Guidance — delete before approval

If the minutes of two reviews in a row could be swapped without anyone noticing, the review has become a ritual. Change the format before the certification body points it out.

The decisions to record

The results of the review (clause 9.3.3 Management review results) are its decisions. Record each one, even where the decision is to change nothing. Top management's part in them is what clause 5.1 Leadership and commitment asks to see.

Ref

Decision

Answers to

MD-1

Conclusion: does the ISMS still fit the organisation, is it enough, and does it work? One sentence each, with the reason.

9.3.1 General; 5.1 Leadership and commitment

MD-2

Improvement opportunities: each one taken up (owner, date) or declined (reason).

9.3.3 Management review results; 10.1 Continual improvement

MD-3

Changes needed to the ISMS: scope, policy, objectives, risk criteria, controls or processes — what changes, who changes it, by when.

9.3.3 Management review results; 6.3 Planning of changes

MD-4

Resources: people, money and time agreed or refused, with the consequence of a refusal stated.

5.1 Leadership and commitment; 7.1 Resources

MD-5

Risks: residual risks the risk owners ask management to accept, accepted or sent back for treatment.

6.1.3 Information security risk treatment

MD-6

In a certification year: go ahead with, or move, the next certification audit.

9.3.3 Management review results

MD-7

The date of the next review.

9.3.1 General

The minutes are the record the standard requires for clause 9.3.3 Management review results, and one of the 8 blocking items in the Certification Readiness Self-Assessment: without a completed review, a Stage 2 audit cannot pass.

Minutes template

Field

Content

Meeting

[[ISMS management review]] — [[first / regular / extra]]

Date, time and place

[[YYYY-MM-DD, hh:mm–hh:mm, room or call]]

Chair

[[Name, role]]

Present

[[Names and roles]]

Apologies and deputies

[[Names; who deputised with what authority]]

Quorum

[[Met / not met]]

Pre-read issued

[[YYYY-MM-DD; list of papers]]

For each agenda item:

Item

What the meeting considered

Discussion — key points only

Decision

Actions

[[MR-n]]

[[The input, in one or two lines, with the paper's reference]]

[[Challenges, disagreements, questions]]

[[What was decided; or 'no change', with the reason]]

[[A-nn]]

Conclusions and decisions (item 8):

Ref

Decision recorded

MD-1

[[Conclusion: …]]

MD-2

[[Improvement opportunities: …]]

MD-3

[[Changes needed to the ISMS: …]]

MD-4

[[Resources: …]]

MD-5

[[Risks: …]]

MD-6

[[In a certification year: …]]

MD-7

[[The date of the next review: …]]

Action log

One log across reviews, carried forward until every action is closed. It is the first paper of the next review (MR-1).

Ref

Action

From item

Owner

Due

Status

Evidence of closure

[[A-nn]]

[[What will be done]]

[[MR-n / MD-n]]

[[Role]]

[[YYYY-MM-DD]]

[[Open / Closed / Overdue / Re-planned]]

[[Reference]]

After the meeting

When

What

Who

Within [[3]] working days

Issue the minutes and the action log to the attendees; the chair confirms them.

ISMS manager

With the minutes

Enter every action in the ISMS Gap & Remediation Tracker (or your own log), so that it is tracked with the other ISMS gaps.

ISMS manager

With the minutes

Tell each action owner who was not present what they own and by when.

ISMS manager

Within [[10]] working days

Update the documents the decisions changed: scope, policy, objectives, Statement of Applicability, risk acceptance records, audit programme.

Document owners

Monthly

Review action progress in the monthly readiness review (IS-10) or the ISMS meeting; escalate an overdue action to the executive sponsor.

ISMS manager

Before the next review

Close or re-plan every action; the log is MR-1.

ISMS manager

A short follow-up note to an action owner:

Field

Content

To

[[Action owner]]

From

[[Name]], ISMS manager

Review and item

[[Management review of YYYY-MM-DD, item MR-n]]

Decision

[[The decision, as minuted]]

Your action

[[A-nn: what, by when]]

Evidence needed to close

[[What will show it is done]]

Worked example — the first management review

EXAMPLE, not part of the template. The organisation is the one used throughout the pack: a software services company with 240 staff in two offices, an NIS2 important entity. Its first internal audit cycle (IA-01, IA-02, IA-03, IA-04, IA-05, IA-06) ran from 4 Nov 2026 to 9 Dec 2026, with the programme summary issued on 23 Dec 2026 (ISMS Internal Audit Programme & Procedure). The review falls 12 calendar days before Stage 1 (18 Jan 2027) and about 8 weeks before Stage 2 (1 Mar 2027). Audit IA-07, on 12 Jan 2027, audits this review. Replace every date, name and figure with your own.

Timetable

Date

Step

23 Dec 2026

Programme summary from the internal audit (EXAMPLE)

23 Dec 2026

Input papers to the ISMS manager (10 working days before) (EXAMPLE)

30 Dec 2026

Pre-read issued (5 working days before) (EXAMPLE)

Wed, 6 Jan 2027, [[10:00–12:00]]

Management review (EXAMPLE)

11 Jan 2027

Minutes and action log issued (3 working days after) (EXAMPLE)

12 Jan 2027

IA-07 audits the review and the corrective action progress (EXAMPLE)

18 Jan 2027

Stage 1

Guidance — delete before approval

The input papers fall due over the year-end holidays in this example. Ask for them before the break, or move the review later — but not so late that the minutes are not ready for IA-07 and for Stage 1.

Agenda — completed

Item

Lead

Paper

Decision sought

0 Opening

[[Chief Executive]] (chair)

—

First management review: no earlier minutes (EXAMPLE)

MR-1 Earlier actions

ISMS manager

—

None: first review. Record that it is the first (EXAMPLE)

MR-2 Changes

Executive sponsor

[[Context record]]

Any change since the scope was approved that affects it? [[e.g. a new product, a new hosting region]] (EXAMPLE)

MR-3 Interested parties

[[Legal or compliance]]

[[Interested parties record]]

[[e.g. new customer contract security terms]]: change needed? (EXAMPLE)

MR-4 Performance

ISMS manager

ISMS Internal Audit Programme & Procedure programme summary; Policy Health & Attestation Reporting Workbook (Security Policy Management pack); Certification Readiness Self-Assessment

Audit results: 6 audits done as planned; 0 major, 15 minor (F-01, F-02, F-03, F-04, F-05, F-06, F-07, F-08, F-09, F-10, F-11, F-12, F-13, F-14, F-15), 1 observation (O-01). Readiness: ISM-01 [[n]] of 8 blocking items operating. Is Stage 1 on? (EXAMPLE)

MR-5 Feedback

[[Account management]]

[[Customer questionnaires received]]

[[Any response or change?]] (EXAMPLE)

MR-6 Risks

[[Risk owners]]

Risk Reporting Dashboard (Information Security Risk Management pack); Risk Treatment Plan (Information Security Risk Management pack)

[[Accept the residual risks put forward?]] Treatment on track? (EXAMPLE)

MR-7 Improvement

ISMS manager

O-01 and other observations

Take up O-01? (EXAMPLE)

8 Decisions

Chair

Summary of decisions sought

MD-1 to MD-7 (EXAMPLE)

9 Close

Chair

Action log

Next review date (EXAMPLE)

Minutes — skeleton

Field

Content

Meeting

ISMS management review — first (EXAMPLE)

Date, time and place

6 Jan 2027, [[10:00–12:00]], [[room]] (EXAMPLE)

Chair

[[Chief Executive]]

Present

[[Chief Executive]]; Chief Operating Officer (executive sponsor); Head of Information Security (ISMS manager); Head of IT; HR Director; Head of Procurement; [[Chief Financial Officer]] (EXAMPLE)

Pre-read issued

30 Dec 2026 (EXAMPLE)

Item

Considered

Decision

Actions

MR-1

First review; no earlier actions.

No earlier actions (EXAMPLE)

—

MR-4 audit results

6 audits, covering every clause from 4 to 10 except 9.3, and every Annex A theme: 0 major and 15 minor nonconformities, raised wherever a requirement was not yet in place. 12 corrected by the review, including F-01 (the policy register: AUP-001, BKP-001 past review, corrected 18 Nov 2026); open: F-03, F-04, F-15. O-01: acknowledgement coverage 94.5% against a 95% target.

Corrective action plans accepted; the executive sponsor to see every open one corrected before Stage 2 (EXAMPLE)

[[A-01]]

MR-4 measurement

PM-01 Documents past review date and PM-03 Acknowledgement coverage from the policy health workbook; [[other measures]].

[[Decision]] (EXAMPLE)

[[A-nn]]

MR-6

[[Top risks and movement]]; the Supplier Security Policy (P04 register SUP-001) [[approved on YYYY-MM-DD / still awaiting approval]].

[[Residual risks accepted or sent back]] (EXAMPLE)

[[A-nn]]

MR-7

O-01: re-acknowledgement after the reviewed Acceptable Use Policy is re-issued.

Taken up; owner HR Director (EXAMPLE)

[[A-02]]

Ref

Decision recorded — EXAMPLE

MD-1

[[The ISMS fits the organisation and its scope; it is enough for the risks assessed; it works, with the nonconformities from the internal audit being corrected.]] (EXAMPLE)

MD-2

O-01 taken up (A-02). [[Other opportunities: taken up or declined, with reasons.]] (EXAMPLE)

MD-3

Supplier controls (A.5.19 to A.5.23) audited every year until the Supplier Security Policy (P04 register SUP-001) has operated for a year; the audit programme updated (ISMS Internal Audit Programme & Procedure, step 22). (EXAMPLE)

MD-4

[[e.g. Contracted auditor retained for the Year 2 audits of clauses 4 to 10.]] (EXAMPLE)

MD-5

[[Residual risks accepted, by reference; or none put forward.]] (EXAMPLE)

MD-6

Stage 1 goes ahead on 18 Jan 2027: the first audit cycle is complete and no major nonconformity is open. 12 of the 15 minor nonconformities are corrected; the other 3 (F-03, F-04, F-15) are in corrective action, the last due to be corrected by 3 Feb 2027, before Stage 2. (EXAMPLE)

MD-7

Next review: [[YYYY-MM]], no later than 12 months after this one. (EXAMPLE)

Related documents

Document

Relationship

ISO 27001 Implementation Methodology & Project Plan

The project plan: the first review closes Phase 5 (Check), before Stage 1

Certification Readiness Self-Assessment

Readiness and the headline measures ISM-01, ISM-02, ISM-03, ISM-04; clause 9.3.3 is a blocking item

ISMS Gap & Remediation Tracker

Where the review's actions are tracked with the other ISMS gaps

ISMS Internal Audit Programme & Procedure

The audit results and nonconformities (MR-4, MR-7); audits this review

Stage 1 and Stage 2 Audit Preparation Guide

What the certification body will ask about the review at Stage 1 and Stage 2

Board Cybersecurity Report Deck Template; Cyber Risk One-Page Board Summary

The board's view of the same risks (MR-2, MR-4); Board Cybersecurity Reporting pack

Risk Reporting Dashboard; Risk Treatment Plan

Risk assessment results and treatment progress (MR-6); Information Security Risk Management pack

Third-Party Risk Dashboard

Supplier changes, performance and feedback (MR-2, MR-4, MR-5); Third-Party Security Risk Management pack

Access Review Outcome Report Template

Access review results (MR-4); User Access Review pack

Policy Health & Attestation Reporting Workbook

Policy currency and acknowledgement measures (MR-4); Security Policy Management pack

Adapting this template

Guidance — delete before approval

Small organisation: top management may be two or three directors. Hold the review as an item of an existing management meeting, with its own minutes, and keep the agenda: the inputs can be one page each and the whole review [[60]] minutes. The decisions still have to be recorded one by one.

Regulated entity: ISO/IEC 27001:2022 is the requirement this pack meets. If you are also subject to NIS2 or DORA, the management body has its own duties to approve and oversee security risk management; this review can feed that oversight, and its minutes are good evidence of it — but a certificate is evidence, not compliance. Agree with [[legal or compliance]] whether the review should report to the board or a board committee, and add any regulatory reporting as an MR-3 item.

IT run by a service provider: ask the provider for its measures, incidents and changes in time for the input papers, and invite its account manager for the MR-4 and MR-5 items where useful. The decisions stay with your management.

Delete this section before approval.

Framework references

These references show where this document supports an external framework. They indicate relevance only and do not reproduce the text of any standard. Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0.

Framework

Reference

Supported by

ISO/IEC 27001:2022

Clause 9.3 — Management review

Whole pack

ISO/IEC 27001:2022

Clause 9.3.1 — General

When it meets; who attends; keeping it a decision meeting

ISO/IEC 27001:2022

Clause 9.3.2 — Management review inputs

The agenda (MR-1 to MR-7); the pre-read pack

ISO/IEC 27001:2022

Clause 9.3.3 — Management review results

The decisions to record (MD-1 to MD-7); minutes template; action log

ISO/IEC 27001:2022

Clause 5.1 — Leadership and commitment

Who attends; decisions on resources and direction (MD-1, MD-4)

NIST CSF 2.0

GV.OV-01 — “Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction”

The agenda and decisions: outcomes reviewed to adjust direction

NIST CSF 2.0

GV.RR-01 — “Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving”

Who attends; keeping it a decision meeting: leadership accountable

Definitions

Term

Meaning in this pack

Action log

The list of actions agreed at management reviews, each with an owner, a due date and a status, carried forward until closed.

Input

A topic the review must consider (MR-1 to MR-7).

Interested party

A person or organisation that can affect, or is affected by, the ISMS: customers, regulators, staff, suppliers, owners.

ISMS

Information security management system: the policies, processes, people and records an organisation uses to manage information security risk.

Management review

The planned meeting at which top management reviews the ISMS and decides what to change.

Nonconformity

A requirement not met — of the standard, or of the organisation's own ISMS documents.

Pre-read

The papers issued before the meeting, so that the meeting can decide rather than be informed.

Quorum

The minimum attendance for the review's decisions to stand.

Residual risk

The risk that remains after treatment; its acceptance is recorded (MD-5).

Stage 1 and Stage 2

The certification body's two audits: first of readiness and documentation, then of the ISMS in operation.

Top management

The people who direct and control the organisation at the highest level: [[e.g. Executive Committee]].