SSS · Information Security Policies & ISMS Law

Who should sign the policies?

Management approval + a record of employee notification (preferably electronic signature/log) is the standard. In the NIS2 world, the management body’s approval record has gained additional…

Updated · July 20261 min readCategory · Information Security Policies & ISMS Law
Short answer

Management approval + a record of employee notification (preferably electronic signature/log) is the standard. In the NIS2 world, the management body’s approval record has gained additional importance.

Management approval + a record of employee notification (preferably electronic signature/log) is the standard. In the NIS2 world, the management body’s approval record has gained additional importance.

Under NIS2 the management body does more than sign off: it must approve the cybersecurity risk measures, oversee their implementation, and undergo training — and it can be held personally liable for failing to. So the approval record should show engagement, not just a signature, and reach the board itself wherever the entity is in scope. The wider frame is ISO/IEC 27001, under which the ISMS policy is expected to be owned by top management and reviewed at regular intervals. Separate acceptance texts for role-based undertakings — IT, HR, supplier access — make it clear where responsibility sits, and are far easier to evidence when an auditor asks.

Shall we apply this matter to your situation?

Tell us your specific situation in a few sentences; we'll assess it with the right team.

Get in touch
This content is for general information only and does not constitute legal advice. Please contact our team for an assessment of your specific circumstances.
Categories
Information Security Policies & ISMS Law

The right start means a predictable process.

From the first meeting to completion of the work; let's plan every step transparently.