1.ensuring the information security policy and the information security objectives are established and are compatible with the strategic direction of the organization;
2.ensuring the integration of the information security management system requirements into the organization’s processes;
3.ensuring that the resources needed for the information security management system are available;
4.communicating the importance of effective information security management and of conforming to the information security management system requirements;
5.ensuring that the information security management system achieves its intended outcome(s);
6.directing and supporting persons to contribute to the effectiveness of the information security management system;
7.promoting continual improvement; and
8.supporting other relevant