ISO 27002:2022 5.2: Information security roles and responsibilities
Information security roles and responsibilities are to be set out and assigned to people in a way that fits what the organization needs. Purpose: create an agreed, approved structure, understood by everyone, for putting information security in place, running it and managing it. Guidance: assignments follow the information security policy and the topic-specific policies, and cover who protects information and associated assets, who carries out particular security processes, who performs risk management and especially who accepts residual risk (such as risk owners), and the duties of everyone who uses the organization's information and assets. Site-level or facility-level detail is added where needed. A person holding a security responsibility may hand tasks to someone else but stays accountable and should confirm the delegated work was done properly. Each area of responsibility is defined, written down and communicated, and authorization levels are documented. People in security roles need the knowledge and skills the role demands and should get support to stay current. Other information notes that many organizations name an information security manager with overall responsibility, that resourcing and implementation often stay with line managers, that asset owners commonly carry day-to-day protection, and that in smaller organizations security may be part of existing jobs rather than a dedicated post.
This control maps to 103 controls across 40 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.OC-01 The organizational mission is understood and informs cybersecurity risk management
NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
NIST-CSF-GV.RR-02 Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced
You are reading one control. How much of ISO 27002:2022 have you already done?
ISO 27002:2022 5.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.