ISO/IEC 27003:2017
Leadership – ISO/IEC 27003:2017

ISO/IEC 27003:2017 ISO27003-5.3: Organizational roles, responsibilities and authorities

Top management makes sure responsibilities and authorities for roles that matter to information security are allocated and made known across the organization. Explanation: the aim is that someone is answerable for the ISMS conforming to ISO/IEC 27001 and someone reports ISMS performance to top management. Guidance: top management should keep checking that ISMS responsibilities and authorities are allocated so the system meets ISO/IEC 27001; it need not allocate every one itself but should delegate the authority to do so adequately and should approve the principal ISMS roles. Responsibilities and authorities should be given for these activities: coordinating how the ISMS is set up, run, kept up, reported on and improved; advising on risk assessment and treatment; designing security processes and systems; setting standards for choosing, configuring and operating controls; handling security incidents; and reviewing and auditing the ISMS. Security responsibilities should also be written into other roles, for example information owners, process owners, asset owners (such as application or infrastructure owners), risk owners, and coordinating functions or persons, which normally support the ISMS; the held copy ends partway through this list.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 13 controls across 12 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 23894:2023 · 2 controls

  • 23894-5.4.3 Roles, Authorities, Responsibilities
  • 5.4.3 Assigning organizational roles, authorities, responsibilities and accountabilities

ISO 14001:2015 · 1 control

  • 5.3 Organizational roles, responsibilities and authorities

ISO 14004:2016 · 1 control

  • 5.3 Organizational roles, responsibilities and authorities

ISO 22000:2018 · 1 control

  • 5.3 Organizational roles, responsibilities and authorities

ISO 22301:2019 · 1 control

  • 5.3 Roles, responsibilities and authorities

ISO 27701:2019 · 1 control

  • 5.3.3 Organizational roles, responsibilities and authorities

ISO 37001:2016 · 1 control

  • 5.3 5.3 Organizational roles, responsibilities and authorities

ISO 37301:2021 · 1 control

  • 5.3 Roles, responsibilities and authorities

ISO 45001:2018 · 1 control

  • 5.3 Organizational roles, responsibilities and authorities

ISO 55001:2014 · 1 control

  • 5.3 Organizational roles, responsibilities and authorities

ISO 9001:2015 · 1 control

  • 5.3 Organizational roles, responsibilities and authorities

ISO/IEC 42001:2023 · 1 control

  • 5.3 Roles, responsibilities and authorities

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Leadership – ISO/IEC 27003:2017

Query this from an agent

The graph holds this control, the 13 it maps to, and the evidence behind each claim, over MCP and REST.