Policy Register

Information security roles and responsibilities

Who owns information security, privacy, continuity and AI decisions, with the authority each role carries and the committee that hears them.

How the register reads it

Also calledRACI, security organisation, terms of reference
FamilyGovernance and the management system
Document typeRecord. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted.
Folds intoThe regimes accept it folded into the information security policy; when neither is listed, the gap is counted once, under the parent.
Expected ownerThe information security lead (CISO or ISMS manager).
Review cadenceAnnual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period).
On the gap list whenISO 27001 or ISO 27701 or ISO 42001 or ISO 22301 or DORA is ticked and no line resolves to it or to its parent.
TemplateNo template yet. The clauses below say what the document is expected to contain.

Which standards require it, and what each expects it to contain

6 requiring clauses, 5 regimes

Shown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim. A clause marked named is one of ISO/IEC 27001:2022's management clauses (4 to 10), named with its title and not quoted here.

ISO/IEC 27001:2022

Named, not quoted: 5.3named Organizational roles, responsibilities and authorities.

ISO 27001 5.2 Information security roles and responsibilities

Name who owns what in security and make the allocation explicit and traceable.

What the ISO 27002 guidance expects the document to say: Requires information security roles and responsibilities to be defined and allocated in line with what the organisation actually needs, so ownership of each security duty is explicit rather than assumed.

Evidence an auditor accepts: The documented allocation of information security roles and responsibilities, naming individuals or positions rather than teams; role descriptions or terms of reference setting out the security duties attached to each role; evidence the allocation was formally approved and communicated to the holders
Common gap: Roles not updated after staff changes
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022

ISO/IEC 27701:2025

ISO 27701 5.3 Roles, responsibilities and authorities

Top management shall ensure that the responsibilities and authorities for roles relevant to the privacy information management system are assigned and communicated within the organization. Top management shall assign the responsibility and authority for ensuring that the PIMS conforms to the requirements of this document, and for reporting on the performance of the PIMS to top management. Roles that jurisdictions can require, such as a data protection officer, and the point of contact for PII principals and for customers are addressed by the controls in Annex A (A.3.4).

Evidence an auditor accepts: Role descriptions assigning PIMS responsibilities and authorities; appointment of the person or function responsible for conformity and for performance reporting; communication of responsibilities to those who hold them
Common gap: Responsibilities assigned but never communicated
Source: ISO/IEC 27701:2025

ISO/IEC 42001:2023

ISO 42001 A.3.2 AI roles and responsibilities

Roles and responsibilities for AI shall be defined and allocated according to the organization's needs.

Evidence an auditor accepts: Role descriptions; rACI matrix; org chart
Common gap: Are AI-specific roles defined or rolled into existing IT roles?
Source: ISO/IEC 42001:2023

ISO 22301:2019

ISO 22301 5.3 Roles, responsibilities and authorities

Top management must assign and communicate the responsibilities and authorities for the roles the BCMS depends on, and must specifically assign responsibility and authority for ensuring the BCMS conforms to the standard and for reporting BCMS performance back to top management.

Evidence an auditor accepts: Role descriptions or a responsibility matrix covering BCMS roles; named individual accountable for BCMS conformity; named reporting line and evidence of performance reporting to top management
Common gap: Roles assigned in a matrix that the holders have never seen
Source: ISO 22301:2019

DORA (Regulation (EU) 2022/2554)

DORA Art. 5 Governance and organisation

The management body of the financial entity shall define, approve, oversee and be responsible for the implementation of the ICT risk management framework, bear ultimate responsibility for managing ICT risk, set roles and responsibilities, approve the digital operational resilience strategy, and allocate appropriate budget and training.

Evidence an auditor accepts: Board-approved ICT risk management framework and digital operational resilience strategy; records of management-body oversight and ICT training
Common gap: No management-body ownership of ICT risk
Source: DORA (Regulation (EU) 2022/2554)

Do this for every document on your list

Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.

Build a register

Information security policy · Internal audit charter and programme