Make managers actively require staff to follow security policies and procedures within their teams. Leadership backing is what turns written rules into everyday practice.
What an auditor, or Sekit's evidence engine, asks for.
Information security policy
The written, leadership-approved document that sets the company's security rules: what is protected, how, and who is responsible.
From the Sekit evidence catalog
In practice
In practice this shows up as line managers folding the security policy into everyday supervision: mentioning it at team meetings, correcting a risky habit on the spot, signing off on exceptions their staff request. Auditors rarely test the policy document itself; they ask a manager to describe how they hold their team accountable and check whether management review meeting minutes exist and get followed up. The common failure mode is a policy that only IT ever mentions, so staff treat it as background noise rather than something their own boss cares about.
Common gaps
Management review meetings happen on paper only: minutes exist but list no decisions, owners or follow-up dates, so nothing traces back to leadership action.
Line managers can name the security policy but cannot describe how they enforce it with their own direct reports.
Executive briefings on security posture are scheduled but skipped when the leadership calendar gets busy, breaking the promised cadence.
Questions your auditor will ask
Can you show a manager actively enforcing the security policy with their team?
Point to team meeting notes or a manager's own record where the policy was raised, or an exception request the manager reviewed and signed.
How does leadership stay informed about security risk and posture?
The information security policy names a briefing cadence, and briefing records show leadership received updates on schedule.
Who is accountable for the security programme, and do they have a mandate to act?
A signed charter names an accountable owner and states the budget and authority granted to that role.
What happens when an exception to policy is requested?
The request goes through a recorded approval flow with a defined expiry date, and expired exceptions get revisited rather than left open.
Where regulation demands it
NIS2 1.2 requires named roles, responsibilities and authorities for security decisions, and managers are who must exercise them day to day.
ENS org.1 requires a leadership-approved security policy, the artifact this control's evidence is built around.
Related controls
Via the shared Sekit CSF topic, not the framework's own index.