GOV-003 Management Commitment and Accountability
Description
A named executive owns the information security programme, security objectives appear in organisational goals and management review of programme status is recorded at defined intervals. A board or an equivalent body independent of management oversees the development and performance of internal control, receives the security programme's status at defined intervals and records what it reviewed and what it decided.
Rationale
Information security requires resource allocation and decision authority that only executive sponsorship can provide; without it the programme has no mandate across business units. Independent oversight is a separate requirement rather than a stronger version of the same one: an executive owner reports on the programme and a board or equivalent body forms a view on it from outside the management line. In a company with no board, the equivalent body is whatever group holds the owners' interest, and its independence from the executives running the programme is the property that matters.
Applicability (9 profiles)
Art. 20(1) of the Directive makes the management body approve the cybersecurity risk-management measures rather than only oversee them, and makes it liable for infringements of Art. 21. Annex point 1.1.1(k) turns the approval into a dated field on the policy, so the evidence is a date and a minute, not a status report.
Framework Mappings (10)
| HIPAA-164.308.a.2 | Assigned Security Responsibility | informative |
| 5.4 | Management responsibilities | full |
| NIS2-Art.20.1 | Management Body Approval and Oversight of Cybersecurity Measures | partial |
| NIS2-CIR-1.2 | Roles, Responsibilities and Authorities | informative |
| NIS2-CIR-2.2 | Compliance Monitoring | informative |
| PM-1 | Information Security Program Plan | partial |
| MG-3.2-007 | Pre-Trained Model Monitoring | MG-3.2-007 | informative |
| GOVERN 2.3 | Executive Leadership Accountability | informative |
| CC1.2 | COSO Principle 2: Exercises Oversight Responsibility | full |
| CC1.5 | COSO Principle 5: Enforces Accountability | partial |
Evidence (3)
Management review meeting minutes or board/executive committee agenda showing security programme status was reviewed by senior management at defined intervals.
Example: Board or executive team meeting minutes (Google Drive / board portal) from the most recent review cycle, with an agenda item for information security, attendance list including a C-level or equivalent, and documented outcomes.
Test: Request the last two management review meeting minutes that include a security agenda item. Verify: (1) a named executive-level attendee is recorded, (2) security programme status or metrics were presented, (3) the review occurred within the defined interval (typically 12 months), (4) action items or decisions are documented.
Documented security objectives aligned to organisational goals, approved by senior management, with the progress recorded against them.
Example: Annual security objectives document (Confluence / OKR tool such as Lattice or Notion), showing named executive sponsor, approval date, and security goals mapped to organisational priorities.
Test: Request the current security objectives and the progress records kept against them. Verify: (1) the objectives are stated with a named executive owner, (2) each objective carries a measure and a target, (3) a progress record exists for at least one objective within the last review cycle, stating the current value against the target, (4) an objective missed at the last review carries a recorded decision to continue, revise or drop it, (5) the objectives are dated within the current review cycle.
Minutes of the board or equivalent independent body recording its review of the information security programme and of the internal control system.
Example: Board minutes, 2026-06-18, agenda item 6, information security programme review
Test: Request the last two sets of minutes carrying a security agenda item. Verify: (1) the body's members are identified and those independent of executive management are distinguishable, (2) security programme status reached the body at the interval the charter or terms of reference set, (3) the minutes record what the body reviewed and what it decided rather than noting the item was tabled, (4) actions the body set are tracked to closure, (5) the body received the material in advance rather than only at the meeting.
Questions (3)
Is your information security programme sponsored by a named executive who is accountable for its direction and resources?
The sponsor should be a C-level executive or equivalent who is named in the security programme documents and receives regular programme status updates.
How frequently does senior management formally review the status of the information security programme?
Management review meetings should produce documented minutes with security agenda items, attendance records, and action items. Annual is the typical minimum.
Does a board or an equivalent body independent of management review the information security programme at a defined interval?
Independence means the body sits outside the management line that runs the programme. Where there is no board, the equivalent body is the group holding the owners' interest, such as an investor committee or an audit committee. Minutes recording what was reviewed and decided are the evidence; an agenda listing the item is not.