Top management makes sure responsibilities and authorities for roles that matter to information security are allocated and made known across the organization. Explanation: the aim is that someone is answerable for the ISMS conforming to ISO/IEC 27001 and someone reports ISMS performance to top management. Guidance: top management should keep checking that ISMS responsibilities and authorities are allocated so the system meets ISO/IEC 27001; it need not allocate every one itself but should delegate the authority to do so adequately and should approve the principal ISMS roles. Responsibilities and authorities should be given for these activities: coordinating how the ISMS is set up, run, kept up, reported on and improved; advising on risk assessment and treatment; designing security processes and systems; setting standards for choosing, configuring and operating controls; handling security incidents; and reviewing and auditing the ISMS. Security responsibilities should also be written into other roles, for example information owners, process owners, asset owners (such as application or infrastructure owners), risk owners, and coordinating functions or persons, which normally support the ISMS; the held copy ends partway through this list.
This control maps to 13 controls across 12 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 13 it maps to, and the evidence behind each claim, over MCP and REST.