The management review is the one meeting ISO 27001 puts on top management personally: not the security team, not the consultant, the people who run the company. It is also the record an auditor opens with a checklist in hand, because Clause 9.3 lists what the review must consider and what it must decide, and the minutes either show each item or they do not. This article reads the clause as an agenda, names the seven inputs and the four trends under one of them, the two outputs, what the minutes have to show, and the mistakes that turn a real meeting into a finding; the free page writes the minutes in the clause's order from the meeting facts, the counts and what was said.

The seven inputs, as an agenda

The inputs are the agenda, in the order the clause lists them. One: the status of the actions from the previous review, each one closed or carried forward with a reason, which is why the first item of every review is the last item of the one before. Two: changes in the external and internal issues that matter to the system, the context of Clause 4.1 read again: a new product, a new hosting region, a regulation that started to apply, a change in headcount. Three: changes in the needs and expectations of interested parties, the item the 2022 edition added, where a customer's new questionnaire, a regulator's expectation or a contract clause lands. Four: feedback on the information security performance, with four trends the clause names, taken next. Five: feedback from interested parties, what customers, auditors, staff, suppliers and authorities said about the system. Six: the results of the risk assessment and the status of the risk treatment plan, the date and outcome of the last assessment, the treatments completed and the residual risks their owners accepted. Seven: opportunities for continual improvement, from anyone. An agenda with these seven headings, in this order, is the clause; a meeting that covers them under other names still has to be mapped back for the auditor.

The four trends under the fourth input

The fourth input is where the numbers live, and the clause names four trends: the nonconformities and what was done about them, the results of the measures the company monitors, the results of its audits, and whether the objectives were met. Each is a line with a figure for the period and a sentence on what it means. Nonconformities: how many were raised, how many closed, and for the open ones the cause and the fix, because Clause 10.2 wants the cause found and the fix checked, not only the correction. Monitoring and measurement: the measures the company chose under Clause 9.1, uptime against the commitment, the phishing test click rate, the access reviews done on time, each against the last period. Audit results: the internal audits held in the period and what they found, with the findings' status. Objectives: how many of the objectives set in the policy were met, and what was decided about the ones that were not. A review that reports these four as figures is one an auditor can read in a minute; a review that reports "security is good" is one they read as a gap.

The two outputs, and what the minutes have to show

The clause asks for two things out of the review: what will be improved, and what the system itself has to change. A good set of minutes adds a third the standard does not name, the resources those decisions need, because a decision without a budget or a person is an intention. The minutes then have to show, for the auditor, that the review happened at a planned interval, who attended and who chaired, that each of the seven inputs was considered, the decisions taken, and the actions with an owner and a date; and they have to be kept as documented information under Clause 7.5, which means a version, an approval and a place. Two consequences follow. The actions of this review are the first input of the next, so the minutes are also the agenda of the meeting a year away. And the review is where the objectives, the risk register and the Statement of Applicability meet: an objective missed becomes an action, a risk accepted becomes a line the owner signed, a control excluded stays justified or comes back in.

The mistakes that turn a meeting into a finding

The review held but not minuted, or minuted as "all topics discussed". An input missing because the agenda used the company's headings and nobody mapped the third input, the interested parties' expectations, onto any of them. The performance input written without figures. Actions without owners or dates, so the next review cannot report their status. Minutes not approved, or approved by the security lead rather than top management, which fails the point of the clause. No review since the last audit, in a company that has changed products, hosting or suppliers since. And the review held two weeks before the certification audit with no previous review to report on, which is allowed for a first audit and is a finding at the second. Each is avoided by using the clause as the agenda and by writing less with figures rather than more without.

What to do with it

Enter the meeting on the free page: the company, the date, the period reviewed, the chair and the attendees; the counts for the four trends; a note for each of the seven inputs, which the page writes as a gap to complete where it is left empty rather than skipping it; the decisions on improvement, changes and resources; and the actions with owner and date. Copy the minutes, have the chair approve and date them, file them as the review's documented information, and put the actions in front of the next review. StandardOS opens the review with the inputs pre-filled from the records it holds, the last review's actions, the period's nonconformities and audits, the objectives with their measures, the risk register's date and residual risks and the interested-party feedback logged, so that top management adds the decisions and signs; the policy sets the objectives the fourth input reports on, the risk register is the sixth input, and the Statement of Applicability is where a change decided here lands.