What must management review cover?
Clause 9.3 requires to review the ISMS at planned intervals for continuing suitability, adequacy, and effectiveness. It is a leadership review of the management system, not a security-team status meeting delegated without management participation.
The must cover previous-review actions; relevant changes in internal and external issues and interested-party needs; performance trends for nonconformities and corrective actions, monitoring and measurement, audit results, and objective fulfilment; interested-party feedback; risk-assessment results; risk-treatment-plan status; and continual-improvement opportunities.
- Use the Clause 9.3.2 inputs as a complete agenda, while adding organization-specific topics where useful.
- Show which members of participated and which ISMS scope the review covered.
- Bring unresolved audit findings, overdue treatments, objective performance, and material context changes to the review with the decision or escalation needed.
- For each trend, show the period, measure, target or comparison basis, result, interpretation, and decision needed. A list of metrics without analysis does not show that evaluated ISMS performance.
ISO/IEC 27001:2022 clauses 9.3.1 and 9.3.2 require top-management review at planned intervals and list the inputs the review must consider.
ISO/IEC 27002:2022 may help interpret control-performance information presented to management, while ISO/IEC 27001 supplies the review requirements.