ISO 37001:2016
Leadership – ISO 37001:2016

ISO 37001:2016 5.3.1: 5.3.1 Roles and responsibilities

Top management carries overall responsibility for putting the system in place and complying with it, as set out in 5.1.2, and makes sure responsibilities and authorities for the relevant roles are assigned and communicated at all levels. Each manager must require that the system is applied and followed in their department or function, and the governing body, top management and everyone else must understand, follow and apply the requirements that bear on their own role.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 27 controls across 24 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 19011:2018 · 2 controls

  • 5.4.1 Roles and responsibilities of the individual(s) managing the audit programme
  • 6.4.2 Assigning roles and responsibilities of guides and observers

ISO/IEC 27043:2015 · 2 controls

  • ISO27043-04 Roles and responsibilities definition
  • ISO27043-5.2 Roles and Responsibilities for Investigations

APRA CPS 234 · 1 control

  • CPS234-14 Definition of Information Security Roles and Responsibilities
  • FFIEC-05 Roles and responsibilities definition

IEC 62443 · 1 control

  • IEC62443-04 Roles and responsibilities for critical systems

ISO 22320:2018 · 1 control

  • ISO-22320-5.4 Roles and responsibilities

ISO 27701:2019 · 1 control

  • 5.3.1 Leadership and commitment

ISO/IEC 27010:2015 · 1 control

  • 27010-6.1 Roles and Responsibilities

ISO/IEC 27014:2020 · 1 control

  • 27014-7.1 Roles and Responsibilities of Governing Body

ISO/IEC 27019:2024 · 1 control

  • ISO27019-04 Roles and responsibilities for critical systems
  • 27050-2.2 Roles and Responsibilities

ISO/IEC 30111:2019 · 1 control

  • 30111-5.3 Roles and responsibilities

ISO/IEC 38500:2024 · 1 control

  • 5.11 Social responsibility

ISO/IEC 42001:2023 · 1 control

  • A.3.2 AI roles and responsibilities

ISO/SAE 21434 · 1 control

  • ISO21434-04 Roles and responsibilities definition

NIST SP 1800-32 · 1 control

NIST SP 800-128 · 1 control

NIST SP 800-150 · 1 control

  • TIS-2 Roles and Responsibilities for Threat Sharing

NIST SP 800-218 · 1 control

PCI DSS 4.0 · 1 control

  • 1.1.2 1.1.2 Requirement 1 roles and responsibilities assigned

PCI P2PE · 1 control

  • PCI-P2PE-05 Roles and responsibilities definition

PCI PIN Security · 1 control

  • PCI-PIN-05 Roles and responsibilities definition

PCI SSF · 1 control

  • PCI-SSF-05 Roles and responsibilities definition

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Leadership – ISO 37001:2016

Query this from an agent

The graph holds this control, the 27 it maps to, and the evidence behind each claim, over MCP and REST.