SSS · Information Security Policies & ISMS Law

Who should sign the policies?

Management approval + a record of employee notification (preferably electronic signature/log) is the standard. In the NIS2 world, the management body’s approval record has gained additional…

Updated · July 20261 min readCategory · Information Security Policies & ISMS Law
Short answer

Management approval + a record of employee notification (preferably electronic signature/log) is the standard. In the NIS2 world, the management body’s approval record has gained additional importance.

Management approval + a record of employee notification (preferably electronic signature/log) is the standard. In the NIS2 world, the management body’s approval record has gained additional importance.

Under NIS2 the management body does more than sign off: it must approve the cybersecurity risk measures, oversee their implementation, and undergo training — and it can be held personally liable for failing to. So the approval record should show engagement, not just a signature, and reach the board itself wherever the entity is in scope. The wider frame is ISO/IEC 27001, under which the ISMS policy is expected to be owned by top management and reviewed at regular intervals. Separate acceptance texts for role-based undertakings — IT, HR, supplier access — make it clear where responsibility sits, and are far easier to evidence when an auditor asks.

Shall we apply this matter to your situation?

Tell us your specific situation in a few sentences; we'll assess it with the right team.

Get in touch →
This content is for general information only and does not constitute legal advice. Please contact our team for an assessment of your specific circumstances.
Categories
Information Security Policies & ISMS Law

The right start means a predictable process.

From the first meeting to completion of the work; let's plan every step transparently.