ISO 27001:2022
Organizational controls – ISO 27001:2022

ISO 27001:2022 5.2: Information security roles and responsibilities

The organization is to define the roles and responsibilities it needs for information security and allocate them to people according to its needs. Purpose (stated in ISO/IEC 27002:2022): creates an approved, understood structure for implementing, operating and managing information security. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.2.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 115 controls across 38 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 13 controls

PCI DSS 4.0 · 12 controls

  • 1.1.2 1.1.2 Requirement 1 roles and responsibilities assigned
  • 11.1.2 11.1.2 Roles for security testing assigned and understood
  • 12.1.4 12.1.4 Executive ownership of information security formally assigned
  • 12.10.1 12.10.1 Incident response plan ready for activation
  • 2.1.2 2.1.2 Requirement 2 roles and responsibilities assigned
  • 4.1.2 4.1.2 Requirement 4 roles and responsibilities assigned
  • 5.1.2 5.1.2 Requirement 5 roles and responsibilities assigned
  • 6.1.2 6.1.2 Requirement 6 roles and responsibilities assigned
  • 7.1.2 7.1.2 Requirement 7 roles and responsibilities assigned
  • 9.1.2 9.1.2 Requirement 9 roles and responsibilities assigned
  • 3.1.2 3.1.2 Assigned duties for Requirement 3 activities
  • 8.1.2 8.1.2 Requirement 8 roles and responsibilities assigned

ISO 27701:2019 · 9 controls

  • 5.2 Context of the organization
  • 5.3.1 Leadership and commitment
  • 5.3.3 Organizational roles, responsibilities and authorities
  • 5.4 Planning
  • 6.3 Organization of information security
  • 6.3.1 Internal organization
  • 6.9.1 Operational procedures and responsibilities
  • 7.3.1 Determining and fulfilling obligations to PII principals
  • 7.3.9 Handling requests

ISO 22301:2019 · 7 controls

  • 4.4 Business continuity management system
  • 5.1 Leadership and commitment
  • 5.2 Policy
  • 5.3 Roles, responsibilities and authorities
  • 7.1 Resources
  • 8.3.4 Resource requirements
  • 8.4.2 Response structure

ISO/IEC 42001:2023 · 7 controls

  • 4.4 AI management system
  • 5.1 Leadership and commitment
  • 5.2 AI policy
  • 5.3 Roles, responsibilities and authorities
  • A.3 Internal organization
  • A.3.2 AI roles and responsibilities
  • A.9.3 Objectives for responsible use of AI system
  • NIST-CSF-GV.OC-01 The organizational mission is understood and informs cybersecurity risk management
  • NIST-CSF-GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders
  • NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • NIST-CSF-GV.RM-05 Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
  • NIST-CSF-GV.RR-01 Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving
  • NIST-CSF-GV.RR-02 Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced

HIPAA Security Rule · 5 controls

CIS Controls v8 · 4 controls

  • CIS-17.1 Designate Personnel to Manage Incident Handling
  • CIS-17.3 Establish and Maintain an Enterprise Process for Reporting Incidents
  • CIS-17.4 Establish and Maintain an Incident Response Process
  • CIS-17.5 Assign Key Roles and Responsibilities

FedRAMP High · 4 controls

  • PS-9 Position Descriptions (PS-9)
  • SA-2 Allocation of Resources
  • SR-1 Policy and Procedures (SR-1)
  • SR-2(1) Supply Chain Risk Management Plan | Establish SCRM Team (SR-2(1))

FedRAMP Moderate · 4 controls

  • PS-9 Position Descriptions (PS-9)
  • SA-2 Allocation of Resources
  • SR-1 Policy and Procedures (SR-1)
  • SR-2(1) Supply Chain Risk Management Plan | Establish SCRM Team (SR-2(1))

NIST SP 800-66 Rev 2 · 4 controls

SOC 2 · 4 controls

  • SOC2-CC1.1 CC1.1 Commitment to integrity and ethical values (COSO principle 1)
  • SOC2-CC1.3 CC1.3 Structures, reporting lines, authorities and responsibilities (COSO principle 3)
  • SOC2-CC1.5 CC1.5 Accountability for internal control responsibilities (COSO principle 5)
  • SOC2-CC2.2 CC2.2 Internal communication of objectives and control responsibilities (COSO principle 14)

NIST SP 800-181 · 3 controls

C5 (Germany) · 2 controls

  • CFTC-SS-2 Enterprise Risk Management and Governance Category
  • CFTC-SS-3 Information Security Category

DORA · 2 controls

ISO/IEC 29100:2024 · 2 controls

  • 29100-6.10 Information security
  • ISO29100-5.10.10 Information Security

NIST SP 800-161 Rev 1 · 2 controls

  • 161R1-PM-2 Information Security Program Leadership Role
  • 161R1-PM-29 Risk Management Program Leadership Roles
  • ANSSI-HYG-39 Designate an Information System Security Officer and Make the Role Known
  • CPS230-14 Board Setting of Senior Manager Roles and Responsibilities

APRA CPS 234 · 1 control

  • CPS234-14 Definition of Information Security Roles and Responsibilities
  • SEC11-BP08 Build a program that embeds security ownership in workload teams
  • AUCDR-IS-STEP1 Step 1 - Define and implement security governance for CDR data
  • GS-1 Align organization roles, responsibilities and accountabilities

CMMC 2.0 · 1 control

EU AI Act · 1 control

ISO 14001:2015 · 1 control

  • 5.2 Environmental policy

ISO 22000:2018 · 1 control

  • 5.2 Policy

ISO 27001:2013 · 1 control

  • A.6.1.1 Information security roles and responsibilities

ISO 27002:2022 · 1 control

  • 5.2 Information security roles and responsibilities

ISO 37001:2016 · 1 control

  • 5.2 5.2 Anti-bribery policy

ISO 37301:2021 · 1 control

  • 5.2 Compliance policy

ISO 45001:2018 · 1 control

  • 5.2 OH&S policy

ISO 55001:2014 · 1 control

ISO 9001:2015 · 1 control

  • 5.2 Policy

NIS2 Directive · 1 control

  • Art.21.2.a Policies on risk analysis and on information system security

NIST SP 800-218 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Organizational controls – ISO 27001:2022

You are reading one control. How much of ISO 27001:2022 have you already done?

ISO 27001:2022 5.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27001:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27001:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 170 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 115 it maps to, and the evidence behind each claim, over MCP and REST.