ISO 27001 · the management review
The management review minutes, written in the order of Clause 9.3
An auditor opens the management review minutes to check that top management looked at each input Clause 9.3 lists and decided something, so this page is that agenda: the seven inputs in order, the four performance trends with their counts, the decisions, the actions with an owner and a date, and the approval, written as minutes you can file.
The counts
The figures the performance trends are written with; leave a count empty and the line asks for it.
The seven inputs
One note per input, in the clause's order, kept on this page and never in the link; an input left empty is written as a gap to complete, so the minutes never silently skip one.
1 Status of the actions from the previous review
Each action from the last minutes, closed or carried forward, with why.
2 Changes in the external and internal issues
What changed in the context since the last review: products, hosting, people, regulation, customers.
3 Changes in the needs and expectations of interested parties
New customer requirements, a regulator's expectation, a contract clause.
4 Feedback on the information security performance
The four trends the clause names, each with its figure for the period.
5 Feedback from interested parties
What customers, auditors, staff, suppliers or authorities said about the system.
6 Results of the risk assessment and status of the risk treatment plan
The last assessment's date and outcome, the treatments completed, the residual risks accepted.
7 Opportunities for continual improvement
What could be simpler, faster or better evidenced, from anyone.
Decisions
The outputs the clause asks for: what improves, what changes in the system, and what it needs.
Actions
Each decision that needs a hand becomes a row with an owner and a date; the next review opens with these.
The minutes
An input written as a gap is better than one silently skipped: the auditor reads the agenda against the clause, not the length of the notes.
# Management review minutes: [company] Held on [to complete], reviewing the period from [to complete] to [to complete]. Chaired by [to complete]. Attending: [to complete]. Written on with the free page on getstandardos.com against Clause 9.3 of ISO/IEC 27001:2022, the inputs in the clause's order. The wording is StandardOS's own; the minutes are the company's record once approved. ## 1. Status of the actions from the previous review Each action from the last minutes, closed or carried forward, with why. [to complete] ## 2. Changes in the external and internal issues What changed in the context since the last review: products, hosting, people, regulation, customers. [to complete] ## 3. Changes in the needs and expectations of interested parties New customer requirements, a regulator's expectation, a contract clause. [to complete] ## 4. Feedback on the information security performance The four trends the clause names, each with its figure for the period. - Nonconformities and corrective actions: [number open and closed in the period] [to complete] - Monitoring and measurement results: [to complete] - Audit results: [internal audits held in the period] [to complete] - Fulfilment of the objectives: [objectives met of those set] [to complete] ## 5. Feedback from interested parties What customers, auditors, staff, suppliers or authorities said about the system. [to complete] ## 6. Results of the risk assessment and status of the risk treatment plan The last assessment's date and outcome, the treatments completed, the residual risks accepted. [to complete] ## 7. Opportunities for continual improvement What could be simpler, faster or better evidenced, from anyone. [to complete] ## Decisions The outputs the clause asks for: what improves, what changes in the system, and what it needs. - Continual improvement decided: [to complete] - Changes to the management system: [to complete] - Resources needed: [to complete] ## Actions No actions were recorded; the decisions above stand without a follow-up. Approved by [to complete] on [date]. These minutes are the documented information of the review; the actions are tracked to the next one. These minutes are written from the entries given. They are not certification advice; the certification body reads the review for the inputs considered and the decisions taken, and the record it accepts is the one the company signs.
StandardOS fills the seven inputs from the records it already holds
In StandardOS the review opens with the inputs pre-filled from the system: the actions from the last review, the nonconformities and audits of the period, the objectives with their measures, the risk register's date and residual risks, and the interested-party feedback logged; top management adds the decisions, signs, and the actions land on the calendar with owners.
The information security policyThe risk registerThe Statement of Applicability