2. Policies and your responsibilities
Roles, and what to do when something doesn't conform
Security responsibilities in an ISO 27001 organisation sit at three levels, and the standard is explicit that all three are needed.
Top management
ISO 27001 places direct requirements on leadership. Top management must set the direction through the information security policy, make sure the ISMS gets the resources and priority it needs, assign roles clearly, and review performance. This is deliberate: security programmes fail when leadership treats them as an IT problem. If your directors take security seriously, that is not corporate theatre, it is a requirement of the standard.
The ISMS or security manager
Most organisations name a person or small team to run the ISMS day to day: maintaining the risk register and policies, coordinating training, managing incidents, preparing for audits, and reporting to leadership. This person is your first port of call for security questions, concerns, and reports. Know who it is in your organisation.
Every employee
The standard requires that everyone doing work under the organisation's control is aware of the security policy, their own contribution to the ISMS, and the consequences of not conforming. In plain terms: follow the policies that apply to you, complete your training, protect the information you handle, and report problems. You are not expected to be a security expert. You are expected to know the rules of your role and to speak up when something is wrong.
Nonconformities are fixed, not hidden
A nonconformity is any situation where practice does not match the requirement: a process skipped, a control not working, a policy that no longer fits reality. The ISO 27001 mindset is that nonconformities are found, recorded, and corrected. They are normal. Every organisation has them, and audits exist to surface them.
What damages an ISMS is concealment. If you realise you have been doing something against policy, or you spot a rule that is impractical and being quietly ignored by everyone, the right move is to raise it with your manager or the security manager. A reported problem gets fixed. A hidden one gets worse, and tends to surface at the worst possible moment, often in front of an auditor.
Check your understanding
A short, optional 5-question quiz on this section. It doesn't block your progress, it's just a quick self-check.
Try the section quiz →› Course contents
What ISO 27001 is
Policies and your responsibilities
Everyday controls
Incidents, audits and improvement