Chapter 6
06Leadership, Policy and Roles
“Security the manager does not adopt becomes advice everyone ignores.”
Clause 5 makes top management directly accountable for the system, not merely its sponsor. The leader links security to business strategy, provides resources, and resolves the conflict between delivery speed and protection requirements. Without that commitment, the system turns into paperwork one person fills in before the audit.
What Does Leadership Actually Do?
- Approves the policy: A short, clear information security policy aligned with the organisation’s direction, committed to requirements and to continual improvement.
- Integrates security into processes: So it becomes part of client intake, project kick-off and delivery, not a separate step at the end.
- Provides resources: Time, budget and people; otherwise everything written stays a promise.
- Communicates and supports: Explains why security matters, and protects whoever reports a mistake instead of punishing them.
The Information Security Policy
A small agency does not need a hundred-page manual. A top-level policy of one or two pages setting out objectives and principles is enough, followed by short topic-specific policies: acceptable use, passwords, remote work, supplier management and the use of AI tools. All are communicated to employees and relevant external parties, and reviewed periodically or after any significant change.
Roles and Responsibilities
Everyone should know their role in protecting assets. In a small organisation one person may hold several roles, but the roles themselves must be named and documented.


Text in this figure
Top management · Commitment, resources · Governance committee · Information security and AI · Security officer · CISO · AI officer · CAIO · Risk owners · Assets, decisions · Champions · Inside teams · Every employee and freelancer: security is a shared responsibility · Figure 7
| Role | Core responsibility |
|---|---|
| Top management | Approval, resources and management review. |
| Information security officer | Running the system, risks and reporting. |
| Asset and risk owners | The treatment decision for each asset and risk. |
| Security champions in teams | Carrying practices into daily work. |
| Every employee and freelancer | Following the policy and reporting incidents. |
2026 Update
When AI enters the work, a new role appears: an AI governance officer or committee that approves permitted tools and reviews high-impact use cases. ISO 42001 explicitly requires this role, and we return to it in Part Five.
Name the owner before you write the control; a control without an owner does not survive.
Lessons Learned
- 1Top management is accountable for the system, not just its sponsor.
- 2A short top-level policy and clear topic policies beat a huge manual nobody reads.
- 3Roles are named and documented even if one person holds them all.
- 4AI governance is a new role added to the structure.
Tip: use ← → to move between sections.

