ISO 27002:2022
Organizational controls – ISO 27002:2022

ISO 27002:2022 5.2: Information security roles and responsibilities

Information security roles and responsibilities are to be set out and assigned to people in a way that fits what the organization needs. Purpose: create an agreed, approved structure, understood by everyone, for putting information security in place, running it and managing it. Guidance: assignments follow the information security policy and the topic-specific policies, and cover who protects information and associated assets, who carries out particular security processes, who performs risk management and especially who accepts residual risk (such as risk owners), and the duties of everyone who uses the organization's information and assets. Site-level or facility-level detail is added where needed. A person holding a security responsibility may hand tasks to someone else but stays accountable and should confirm the delegated work was done properly. Each area of responsibility is defined, written down and communicated, and authorization levels are documented. People in security roles need the knowledge and skills the role demands and should get support to stay current. Other information notes that many organizations name an information security manager with overall responsibility, that resourcing and implementation often stay with line managers, that asset owners commonly carry day-to-day protection, and that in smaller organizations security may be part of existing jobs rather than a dedicated post.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 103 controls across 40 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 13 controls

  • 1.1.2 1.1.2 Requirement 1 roles and responsibilities assigned
  • 11.1.2 11.1.2 Roles for security testing assigned and understood
  • 12.1.4 12.1.4 Executive ownership of information security formally assigned
  • 12.4.2.1 12.4.2.1 Documentation of quarterly operational reviews
  • 12.8.5 12.8.5 Responsibility allocation between entity and TPSPs
  • 2.1.2 2.1.2 Requirement 2 roles and responsibilities assigned
  • 4.1.2 4.1.2 Requirement 4 roles and responsibilities assigned
  • 5.1.2 5.1.2 Requirement 5 roles and responsibilities assigned
  • 6.1.2 6.1.2 Requirement 6 roles and responsibilities assigned
  • 7.1.2 7.1.2 Requirement 7 roles and responsibilities assigned
  • 9.1.2 9.1.2 Requirement 9 roles and responsibilities assigned
  • 3.1.2 3.1.2 Assigned duties for Requirement 3 activities
  • 8.1.2 8.1.2 Requirement 8 roles and responsibilities assigned

NIST SP 800-53 Rev 5 · 10 controls

ISO 27701:2019 · 6 controls

  • 5.2.4 Information security management system
  • 5.3.1 Leadership and commitment
  • 5.3.3 Organizational roles, responsibilities and authorities
  • 5.5 Support
  • 6.5.1 Responsibility for assets
  • 6.9.1 Operational procedures and responsibilities

ISO/IEC 42001:2023 · 6 controls

  • 5.3 Roles, responsibilities and authorities
  • 6.1 Actions to address risks and opportunities
  • A.3 Internal organization
  • A.3.2 AI roles and responsibilities
  • A.4.6 Human resources
  • A.9.3 Objectives for responsible use of AI system

ISO 22301:2019 · 4 controls

  • 4.4 Business continuity management system
  • 5.1 Leadership and commitment
  • 5.3 Roles, responsibilities and authorities
  • 8.4.2 Response structure

SOC 2 · 4 controls

  • SOC2-CC1.3 CC1.3 Structures, reporting lines, authorities and responsibilities (COSO principle 3)
  • SOC2-CC1.5 CC1.5 Accountability for internal control responsibilities (COSO principle 5)
  • SOC2-CC2.2 CC2.2 Internal communication of objectives and control responsibilities (COSO principle 14)
  • SOC2-CC5.3 CC5.3 Deploying controls through policies and procedures (COSO principle 12)

APRA CPS 234 · 3 controls

  • CPS234-13 Board Responsibility for Information Security
  • CPS234-14 Definition of Information Security Roles and Responsibilities
  • CPS234-P19 Policy Direction to All Responsible Parties
  • ISM-0714 Appointment of a CISO
  • ISM-1071 Designated system owners
  • ISM-1997 Defining cyber security roles and responsibilities

C5 (Germany) · 3 controls

FedRAMP High · 3 controls

  • PL-2 System Security and Privacy Plans
  • PS-9 Position Descriptions (PS-9)
  • SR-2(1) Supply Chain Risk Management Plan | Establish SCRM Team (SR-2(1))

FedRAMP Moderate · 3 controls

  • PL-2 System Security and Privacy Plans
  • PS-9 Position Descriptions (PS-9)
  • SR-2(1) Supply Chain Risk Management Plan | Establish SCRM Team (SR-2(1))

HIPAA Security Rule · 3 controls

  • NIST-CSF-GV.OC-01 The organizational mission is understood and informs cybersecurity risk management
  • NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • NIST-CSF-GV.RR-02 Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced

NIST SP 800-181 · 3 controls

NIST SP 800-66 Rev 2 · 3 controls

  • CFTC-SS-2 Enterprise Risk Management and Governance Category
  • CFTC-SS-3 Information Security Category

CIS Controls v8 · 2 controls

  • CIS-17.1 Designate Personnel to Manage Incident Handling
  • CIS-17.5 Assign Key Roles and Responsibilities

DORA · 2 controls

ISO/IEC 29100:2024 · 2 controls

  • 29100-6.10 Information security
  • ISO29100-5.10.10 Information Security

NIST SP 800-161 Rev 1 · 2 controls

  • 161R1-PM-2 Information Security Program Leadership Role
  • 161R1-PM-29 Risk Management Program Leadership Roles
  • B.6.5 B.6.5 System ownership and division of responsibility
  • ANSSI-HYG-39 Designate an Information System Security Officer and Make the Role Known
  • CPS230-14 Board Setting of Senior Manager Roles and Responsibilities
  • SEC11-BP08 Build a program that embeds security ownership in workload teams
  • AUCDR-IS-STEP1 Step 1 - Define and implement security governance for CDR data
  • GS-1 Align organization roles, responsibilities and accountabilities

CMMC 2.0 · 1 control

  • IS-II.C.1 Information Security Roles and Responsibilities

ISO 27001:2022 · 1 control

  • 5.2 Information security roles and responsibilities

ISO 27018:2019 · 1 control

  • 6.1.1 Information security roles and responsibilities

MTCS (Singapore) · 1 control

  • 6.3 Management of information security

NIS2 Directive · 1 control

  • Art.21.2.a Policies on risk analysis and on information system security

NIST SP 800-218 · 1 control

NY DFS 23 NYCRR 500 · 1 control

  • §500.4 Cybersecurity Governance (CISO)
  • TSA-SD-01 TSA Cybersecurity Coordinator designation
  • TSA-PSG-01 Corporate security programme
  • MTSA-105.200 Facility Security Officer Responsibilities

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Organizational controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 5.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 103 it maps to, and the evidence behind each claim, over MCP and REST.