Information security roles and responsibilities
Who owns information security, privacy, continuity and AI decisions, with the authority each role carries and the committee that hears them.
How the register reads it
| Also called | RACI, security organisation, terms of reference |
|---|---|
| Family | Governance and the management system |
| Document type | Record. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted. |
| Folds into | The regimes accept it folded into the information security policy; when neither is listed, the gap is counted once, under the parent. |
| Expected owner | The information security lead (CISO or ISMS manager). |
| Review cadence | Annual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period). |
| On the gap list when | ISO 27001 or ISO 27701 or ISO 42001 or ISO 22301 or DORA is ticked and no line resolves to it or to its parent. |
| Template | No template yet. The clauses below say what the document is expected to contain. |
Which standards require it, and what each expects it to contain
6 requiring clauses, 5 regimesShown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim. A clause marked named is one of ISO/IEC 27001:2022's management clauses (4 to 10), named with its title and not quoted here.
ISO/IEC 27001:2022
Named, not quoted: 5.3named Organizational roles, responsibilities and authorities.
ISO 27001 5.2 Information security roles and responsibilitiesName who owns what in security and make the allocation explicit and traceable.
What the ISO 27002 guidance expects the document to say: Requires information security roles and responsibilities to be defined and allocated in line with what the organisation actually needs, so ownership of each security duty is explicit rather than assumed.
Common gap: Roles not updated after staff changes
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO/IEC 27701:2025
ISO 27701 5.3 Roles, responsibilities and authoritiesTop management shall ensure that the responsibilities and authorities for roles relevant to the privacy information management system are assigned and communicated within the organization. Top management shall assign the responsibility and authority for ensuring that the PIMS conforms to the requirements of this document, and for reporting on the performance of the PIMS to top management. Roles that jurisdictions can require, such as a data protection officer, and the point of contact for PII principals and for customers are addressed by the controls in Annex A (A.3.4).
Common gap: Responsibilities assigned but never communicated
Source: ISO/IEC 27701:2025
ISO/IEC 42001:2023
ISO 42001 A.3.2 AI roles and responsibilitiesRoles and responsibilities for AI shall be defined and allocated according to the organization's needs.
Common gap: Are AI-specific roles defined or rolled into existing IT roles?
Source: ISO/IEC 42001:2023
ISO 22301:2019
ISO 22301 5.3 Roles, responsibilities and authoritiesTop management must assign and communicate the responsibilities and authorities for the roles the BCMS depends on, and must specifically assign responsibility and authority for ensuring the BCMS conforms to the standard and for reporting BCMS performance back to top management.
Common gap: Roles assigned in a matrix that the holders have never seen
Source: ISO 22301:2019
DORA (Regulation (EU) 2022/2554)
DORA Art. 5 Governance and organisationThe management body of the financial entity shall define, approve, oversee and be responsible for the implementation of the ICT risk management framework, bear ultimate responsibility for managing ICT risk, set roles and responsibilities, approve the digital operational resilience strategy, and allocate appropriate budget and training.
Common gap: No management-body ownership of ICT risk
Source: DORA (Regulation (EU) 2022/2554)
Do this for every document on your list
Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.
Build a registerInformation security policy · Internal audit charter and programme