What is a management review?
A management review is a scheduled meeting where senior leadership evaluates the security program: its performance, risks, audit results, and needed changes. ISO/IEC 27001 clause 9.3 requires it at planned intervals. The output is recorded decisions and actions.
What the buyer is really asking
Management review is where leadership looks at the security program, its metrics, and its risks, and makes decisions. Give the cadence, who attends, and what the output is. ISO 27001 requires it, and SOC 2 auditors look for evidence of the same oversight.
Other ways buyers ask it
Every one of these wants the same answer:
- “Describe your management review process.”
- “How often does leadership review the security program?”
- “Does the board receive security reporting?”
Evidence to have ready
- Management review agendas and minutes
- The security report presented to leadership
How Tyrvar answers this
Tyrvar treats every wording above as one question. You write the answer once, attach the evidence, and revisit it when your setup changes. Each buyer gets that approved answer no matter how their questionnaire words it. If you have not answered it yet, Tyrvar flags the question for you and does not make something up. Try it on your own questionnaire.