Management Review Agenda and Minutes
Mrm No. Doc. No.
MEETING: ISO 27001:2013 Management Review Meeting
Name Title Here Name Title Here
DATE, TIME, PLACE: Date Time Place
ROLES: Chair Facilitator Minute Taker
PREPARATION: Documentation review, audit review and analysis, ISMS objective performance, analysis and
feedback review.
MATERIALS TO BRING: Minutes of previous meeting.
ISMS documentation (ISMS MANUAL and procedures).
All internal and external audit reports.
MEETING OBJECTIVE: Senior management review of the ISMS to ensure suitability, adequacy and effectiveness.
The review is to include the assessment of opportunities for improvement and any potential
changes to the ISMS, including ISMS policy and objectives, and their alignment with
business objectives and strategy.
REVIEW AGENDA: A)- the status of actions from previous management reviews
changes in external and internal issues that are relevant to the
B)- information security management system;
feedback on the information security performance, including trends
in:
1) nonconformities and corrective actions
2) monitoring and measurement results; audit results; and
3) fulfilment of information security objectives;
C)- feedback from interested parties;
D)- results of risk assessment and status of risk treatment plan; and
E)- opportunities for continual improvement.
F)- Any other points for improvements
Next Meeting Decision
Date Time Place
Chair Facilitator Minute Taker
Management Review Agenda and Minutes 1
Management Review Agenda and Minutes
MINUTES: MR/F-2/9.3
TARGET DATE / RESPONSIBILITY
AGENDA ITEM OUTCOMES / DECISIONS
A)-
The status of actions from
previous management reviews
B)-
Changes in external and
internal issues that are relevant
to the information security
management system;
C)-
Feedback on the information
security performance, including
trends in:
1) Nonconformities and
corrective actions
2) Monitoring and
measurement results;
audit results;
3) Fulfilment of
information security
objectives;
Management Review Agenda and Minutes 2
Management Review Agenda and Minutes
TARGET DATE / RESPONSIBILITY
AGENDA ITEM OUTCOMES / DECISIONS
D)-
FEEDBACK FROM INTERESTED
PARTIES
E)-
Results of risk assessment and
status of risk treatment plan;
and Oppurtunity
F)-
Opportunities for continual
improvement.
Management Review Agenda and Minutes 3
Management Review Agenda and Minutes
TARGET DATE / RESPONSIBILITY
AGENDA ITEM OUTCOMES / DECISIONS
G)-
Techniques or procedures which
could be used in the organization to
improve the effectiveness of the
ISMS
H)- Any other points for
improvements
Summary of Review Outputs
Modification of procedures & controls that effect information security, as necessary, to respond to internal or external events that
may impact on the ISMS,
Improvements to how the effectiveness of controls is being measured
Required audits –
Resource needs –
Training requirements - Approach to training continues to be improved with an appropriate level of information being
recorded. Improvements in Training Matrix and induction process ongoing.
Management Review Agenda and Minutes 4
Management Review Agenda and Minutes
Signed: ………………………………………. Signed: ……………………………………………
Top Magaemnt ISR
Date: ……………………….. Date: ………………………….
Management Review Agenda and Minutes 5