Top management must ensure clear responsibilities / authority on at least the following themes:
- who is primarily responsible for ensuring that the information security management system complies with the information security requirements
- who act as ISMS theme owners responsible for the main themes of the information security management system
- who has the responsibility and authority to report to top management on the performance of the information security management system
- who is authorized to carry out internal audits
The ISMS theme owners are presented on the desktop of the management system and in the Information security policy report.
In addition, top management shall ensure that all roles relevant to information security, as well as related responsibilities and authorities, are defined and communicated.