Skip to content
Singahi

Compliance · guide

ISO 27001 A.5.2: Information Security Roles and Responsibilities

80 min read

Share
On this page

Quick Reference (60 Seconds)

Control: A.5.2, Information Security Roles and Responsibilities
Purpose: Establish, document, and communicate information security roles and responsibilities to ensure accountability and clarity across the organization.
ISO 27002 attributes: Control type: Preventive · Properties: Confidentiality, Integrity, Availability · Concepts: Identify · Capabilities: Governance · Domains: Governance and ecosystem, Protection, Resilience
Who it applies to: All employees, contractors, and third-party users who handle information or have access to information systems.
Minimum viable actions:

  • Define a formal Information Security Roles and Responsibilities document
  • Assign specific security responsibilities to roles, not just individuals
  • Communicate responsibilities to all personnel at onboarding and annually
  • Include security responsibilities in job descriptions and performance evaluations
  • Establish a security governance structure with clear accountability

Key deliverables: Roles and Responsibilities Matrix, Job Description Security Addenda, Security Governance Charter, Onboarding Security Briefing, Annual Security Accountability Report.

Audit questions you should be able to answer:

  • Are security roles and responsibilities formally defined and documented?
  • Do all employees understand their security responsibilities?
  • Are security responsibilities included in job descriptions?
  • Is there a security governance structure with clear accountability?
  • Are security responsibilities reviewed and updated regularly?

What the Control Asks For

Do you need this control?

A.5.2 is not mandatory in itself: under clause 6.1.3 you include it if your risk assessment calls for it, and record the decision in your Statement of Applicability. Almost always included, because clause 5.3 already requires top management to assign responsibilities and authorities for the ISMS. A.5.2 extends that to day-to-day security roles. A very small organisation can satisfy it with a short roles table instead of a full RACI.

Annex A 5.2 asks organizations to define and assign information security roles and responsibilities to fit the organization's needs.

Clause 5.3 vs A.5.2. ISO 27001 clause 5.3, which applies to every ISMS, requires top management to assign and communicate responsibility and authority for making the ISMS conform to the standard and for reporting its performance. A.5.2 goes further: security roles and responsibilities across the whole organisation.

In our own words, ISO 27002 says roles should be allocated in line with your policies (A.5.1), covering responsibility for:

  1. Protecting information and other assets (typically through asset owners)
  2. Running specific security processes
  3. Risk management, especially accepting residual risk, which belongs to risk owners
  4. Everyone who uses the organisation's information and assets

It also says: add site-specific detail where needed; people may delegate tasks but stay accountable and should check delegated work is done; each area of responsibility, and the authorisation levels, should be defined, documented and communicated; and people in security roles must be competent and supported to stay up to date. Security can be a dedicated role or an extra duty, depending on your size.

What the Standard Does NOT Require

  • The standard does not mandate specific job titles or organizational structures
  • It does not require a dedicated CISO (though this is recommended for larger organizations)
  • It does not specify how many security roles are needed (this depends on organization size and risk)
  • It does not require external security staff (internal or outsourced is acceptable)
  • It does not mandate specific reporting lines for security roles

Why Information Security Roles and Responsibilities Matter

The Accountability Gap

When security responsibilities are unclear, several critical problems emerge:

  • No one owns security: Security becomes an orphan function that no one actively manages
  • Blame diffusion: When incidents occur, no one takes responsibility because "it wasn't my job"
  • Reactive security: Security is only addressed after incidents, not proactively
  • Resource gaps: Critical security functions are left unfilled because no one knew they needed to be done
  • Compliance failures: Audits reveal gaps because no one was responsible for maintaining controls
  • Inconsistent practices: Different departments handle security differently because there's no unified responsibility

The Business Impact of Unclear Security Roles

Impact TypeDescriptionQuantifiable Cost
Security incidentsNo owner = no prevention = more incidentsAverage breach cost USD 4.88 million worldwide (IBM Cost of a Data Breach Report 2024)
Compliance penaltiesMissing controls because no one was responsibleCommercial
Operational inefficiencyDuplication or gaps in security activitiesWasted effort and unowned tasks
Delayed incident responseNo incident owner = slow responseIBM's 2024 report put the average time to identify and contain a breach at 258 days
Employee confusionStaff don't know what to do or who to askSupport tickets, mistakes, workarounds
Management blind spotsNo one reports security status to leadershipUnmanaged risk accumulation
Failed auditsMissing evidence because no one maintained itAudit remediation costs, lost certifications

The Indian Context

Indian organizations face unique challenges in defining security roles:

  • Smaller organizations: Many Indian SMEs lack dedicated security staff; security is an additional duty for IT managers
  • Family-run businesses: Decision-making is centralized, but security responsibilities may not be formally defined
  • Rapid growth: Startups scale quickly without formalizing security roles, creating accountability gaps
  • Regulatory complexity: RBI, SEBI, IRDAI, and DPDP Act each impose different security requirements, requiring clear ownership
  • Skills shortage: Shortage of qualified security professionals in India means roles may be unfilled or underqualified
  • Cost sensitivity: Organizations may avoid creating dedicated security roles to save costs, creating long-term risk
  • Outsourcing: Many organizations outsource security functions, but unclear accountability between internal and external parties creates gaps
  • Digital India: Government digital services require clear security ownership but government structures may not have defined security roles

Scope and Applicability

In Scope

This control applies to all security roles and responsibilities across the organization:

  • Executive roles: Board, CEO, CISO, CIO, CTO, CFO, COO security responsibilities
  • Security function roles: Security Manager, Security Analyst, Security Engineer, SOC Analyst, Incident Responder, Security Architect
  • IT roles: System Administrator, Network Administrator, Database Administrator, Cloud Engineer, DevOps Engineer
  • Business roles: Data Owner, Process Owner, Business Unit Head, Project Manager, Product Owner
  • Support roles: HR, Legal, Finance, Procurement, Facilities security responsibilities
  • End-user roles: All employees, contractors, temporary staff, interns
  • Third-party roles: Vendors, consultants, outsourced security providers, managed security service providers (MSSPs)
  • Specialized roles: Privacy Officer, Compliance Officer, Risk Manager, Business Continuity Manager, Physical Security Manager
  • Committee roles: Security Committee members, Risk Committee members, Audit Committee members

Applicability by Organization Size

Organization SizeSecurity Roles ApproachTypical Roles
Micro (< 10 employees)Security responsibilities assigned to founder/CEO as an additional duty, possibly with external consultantCEO (security owner), External advisor
Small (10-50 employees)Part-time security role, often combined with IT manager or operations managerIT Manager (security), Data Owner (department heads)
Medium (50-250 employees)Dedicated security role (0.5-1 FTE), possibly part-time CISO or security managerCISO/Security Manager (part-time), IT security coordinator, Data owners
Large (250-1000 employees)Full-time CISO, dedicated security team (3-5 members), clear governance structureCISO, Security Manager, Security Analysts, SOC Analyst, Data Owners, System Owners
Enterprise (1000+ employees)Full security organization with multiple teams, enterprise CISO, regional security officers, specialized rolesCISO, Security Directors, Security Managers, Security Engineers, SOC Team, Incident Response Team, GRC Team, Privacy Team, Security Architects

Applicability by Industry

IndustryKey Security RolesRegulatory Drivers
Banking & Financial ServicesCISO, IT Security Officer, Fraud Manager, RBI Compliance OfficerRBI Cybersecurity Framework, PCI DSS, DPDP Act
InsuranceCISO, Information Security Officer, IRDAI Compliance OfficerIRDAI Guidelines, DPDP Act
Securities & MarketsCISO, CTO Security, Trading Security Officer, SEBI ComplianceSEBI CSCRF (2024), DPDP Act
HealthcareCISO, privacy contact or DPO, patient-data owner, clinical systems security leadDPDP Act, Clinical Establishments (Registration and Regulation) Act 2010, ABDM
IT & SoftwareCISO, Security Architect, DevSecOps Lead, Product Security OfficerISO 27001, SOC 2, DPDP Act
E-commerceCISO, Payment Security Officer, Customer Data Protection OfficerPCI DSS, DPDP Act
GovernmentCISO, CERT-In Coordinator, Digital Security OfficerIT Act, CERT-In Guidelines, DPDP Act
ManufacturingCISO, OT Security Officer, ICS Security Engineer, Physical Security ManagerISO 27001, Industry-specific regulations
EducationCISO, Student Data Protection Officer, Research Security OfficerDPDP Act, UGC guidelines
StartupsFounder/CTO (security), External Security Advisor, DevSecOps LeadInvestor requirements, DPDP Act, ISO 27001

Key Definitions and Terminology

TermDefinition
Information Security RoleA defined function or position within the organization with specific information security responsibilities
ResponsibilityAn obligation to perform a specific security task or function
AccountabilityUltimate ownership of a security outcome; the person who must answer for results
AuthorityThe power to make decisions, allocate resources, or enforce compliance related to security
CISO (Chief Information Security Officer)The senior executive responsible for the organization's information security program
Data OwnerThe business role accountable for a specific data asset's classification, protection, and access control
System OwnerThe role accountable for a specific information system's security, availability, and compliance
Security ManagerThe role responsible for day-to-day management of the security program
Security AnalystThe role responsible for analyzing security data, threats, and incidents
SOC AnalystSecurity Operations Center analyst responsible for monitoring and initial incident response
Security ArchitectThe role responsible for designing security into systems and infrastructure
Incident ResponderThe role responsible for managing and resolving security incidents
Privacy OfficerThe role responsible for data privacy and protection compliance
Compliance OfficerThe role responsible for ensuring regulatory and standard compliance
Risk OwnerThe role accountable for a specific risk and its treatment
Security CommitteeA cross-functional group that oversees security governance and strategy
RACI MatrixA matrix that defines who is Responsible, Accountable, Consulted, and Informed for each activity
Job DescriptionA formal document describing the duties, responsibilities, and qualifications of a role
Security CharterA formal document defining the security governance structure, roles, and reporting relationships
Delegated AuthorityThe transfer of specific security decision-making power to another role
Security CultureThe collective security attitudes, behaviors, and norms of the organization
Segregation of Duties (SoD)The principle that no single individual should have complete control over a critical process (see A.5.3)
Security CompetencyThe skills, knowledge, and abilities required to perform security responsibilities
Performance IndicatorA measurable metric used to evaluate how well a role is performing its security responsibilities
Security Reporting LineThe organizational chain of command for security matters
Dotted-Line ResponsibilityA secondary reporting relationship (e.g., regional CISO reports to global CISO with dotted line)
Security LiaisonA person in a business unit who serves as the point of contact for security matters
Third-Party Security OfficerA role in a vendor organization responsible for the security of services provided to your organization

Relationship to Other Controls

ControlRelationship
A.5.1, Policies for information securityRoles and responsibilities must be defined to implement and enforce policies
A.5.3, Segregation of dutiesSecurity roles must be designed to enforce segregation of duties
A.5.4, Management responsibilitiesManagement roles must include specific security responsibilities
A.5.5, Contact with authoritiesSecurity roles should include regulatory and authority contact (CERT-In, police, regulators)
A.5.6, Contact with special interest groupsSecurity roles should include liaison with external security groups
A.5.7, Threat intelligenceThreat intelligence responsibilities must be assigned to specific roles
A.5.8, Information security in project managementSecurity roles must be included in project governance
A.5.9, Inventory of information and other associated assetsAsset ownership roles must be defined
A.5.10, Acceptable use of information and other associated assetsUser responsibilities must be defined and communicated
A.5.11, Return of assetsRoles responsible for asset return must be defined
A.5.12 and A.5.13, Classification and labellingOwners responsible for classifying and labelling information must be defined
A.5.15, Access controlAccess control roles (requester, approver, reviewer) must be defined
A.5.24, Information security incident management planning and preparationIncident response roles must be defined
A.5.25, Assessment and decision on information security eventsEvent triage and classification roles must be defined
A.5.18, Access rightsRoles that approve and review access rights must be defined
Clauses 6.1.2 and 6.1.3, Risk assessment and treatmentRisk owners who accept residual risk must be named
A.5.30, ICT readiness for continuityBusiness continuity security roles must be defined
A.5.31, Legal, statutory, regulatory and contractual requirementsCompliance roles must be defined
A.5.36, Compliance with policies, rules and standardsCompliance monitoring roles must be defined
A.5.37, Documented operating proceduresRoles responsible for procedure development and maintenance must be defined
A.6.1, ScreeningRoles responsible for background checks must be defined
A.6.2, Terms and conditions of employmentSecurity responsibilities in employment contracts must be defined
A.6.3, Information security awareness, education and trainingRoles responsible for training must be defined
A.6.4, Disciplinary processRoles responsible for enforcing security consequences must be defined
A.6.5, Responsibilities after termination or change of employmentRoles responsible for offboarding must be defined
A.6.6, Confidentiality or non-disclosure agreementsRoles responsible for NDAs must be defined
A.6.7, Remote workingRoles responsible for remote work security must be defined
A.6.8, Information security event reportingRoles responsible for event reporting and triage must be defined
A.8.2, Privileged access rightsRoles responsible for privileged access management must be defined
A.8.15, LoggingRoles responsible for logging and log review must be defined
A.8.16, Monitoring activitiesRoles responsible for security monitoring must be defined
Clause 10.2 and A.5.27, Root cause analysisNonconformities and incidents need root-cause analysis (clause 10.2, A.5.27); the roles that perform it must be defined

Framework Mapping

FrameworkRelevant Control / Reference
NIST CSF 2.0GV.RR-01 to GV.RR-04 (Roles, Responsibilities and Authorities), GV.OV (Oversight)
NIST SP 800-53 Rev 5PM-1 (Information Security Program Plan), PM-2 (Information Security Program Leadership), PM-3 (Information Security and Privacy Resources), AT-3 (Role-Based Training), PS-6 (Access Agreements), PS-7 (Personnel Screening)
COBIT 2019EDM01 (Ensured Governance Framework Setting and Maintenance), APO01.02 (roles and responsibilities), APO07 (Managed Human Resources)
ITIL 4Service Management Practices, Organizational Change Management, Workforce and Talent Management
CIS Controls v8Control 14 (Security Awareness and Skills Training), Control 17 (Incident Response Management, 17.1 designate personnel)
PCI DSS v4.0.1Req 12.1.3 (security roles and responsibilities defined and acknowledged), Req 12.1.4 (executive responsibility assigned)
GDPRArt 37 (DPO Designation), Art 39 (DPO Tasks)
DPDP Act 2023Section 8(5) (reasonable security safeguards), Section 8(4) (technical and organisational measures), Section 10 (DPO for Significant Data Fiduciaries); requires clear accountability
RBI Cybersecurity FrameworkSection on Roles and Responsibilities, Information Security Governance
SEBI CSCRF (2024)Governance requirements for cybersecurity roles
HIPAASecurity Official and Privacy Official requirements

Implementation Roadmap (Week-by-Week)

Figure · Tiers

Maturity levels for roles and responsibilities

Maturity levels for ISO 27001 A.5.2, roles and responsibilities, from most to least mature: Optimizing, security roles continuously refined; Quantitatively Managed, security role performance measured; Defined, formal security roles, responsibilities; Managed, basic security role defined; Ad-hoc, no formal security roles.
Where most organisations sit, and what the next level asks for. Full characteristics per level are in the table below.

Phase 1: Assessment and Design (Weeks 1–4)

Week 1: Current State Assessment

  • Inventory existing security roles, both formal and informal
  • Identify who currently handles security tasks, even if not in their job description
  • Map current security responsibilities to roles
  • Identify gaps (security functions with no assigned owner)
  • Identify overlaps (multiple people doing the same security task without coordination)
  • Review organizational structure and reporting lines
  • Assess current security governance (committees, boards, reporting)
  • Document findings in a gap analysis report

Week 2: Security Governance Design

  • Design security governance structure (committees, reporting lines, escalation paths)
  • Define security roles needed for the organization's size and risk profile
  • Define responsibilities for each role using RACI principles
  • Design reporting structure for security roles (CISO reporting line, dotted-line relationships)
  • Define security committee structure and membership
  • Define authority levels for security decisions (who can approve what)
  • Design security role communication and coordination mechanisms

Week 3: Role Definition

  • Create detailed role descriptions for each security role
  • Define security responsibilities for existing non-security roles (IT, HR, Legal, Finance, etc.)
  • Define security responsibilities for business roles (Data Owner, Process Owner, Business Unit Head)
  • Define security responsibilities for end users
  • Define security responsibilities for third-party roles
  • Create RACI matrix for security activities across all roles
  • Create accountability matrix mapping security controls to roles

Week 4: Documentation and Approval

  • Draft the Information Security Roles and Responsibilities document
  • Draft the Security Governance Charter
  • Draft updated job descriptions with security addenda
  • Draft the Security Committee Charter
  • Review with stakeholders (HR, Legal, Management, IT)
  • Revise based on feedback
  • Obtain formal approval from leadership

Deliverables: Gap analysis, Governance design, Role definitions, RACI matrix, Draft policy and charter

Phase 2: Communication and Integration (Weeks 5–8)

Week 5: Communication Plan

  • Develop communication plan for rolling out new roles and responsibilities
  • Create employee communication materials (emails, presentations, FAQs)
  • Prepare manager briefing materials
  • Schedule town halls, team meetings, and one-on-ones
  • Develop intranet or knowledge base content

Week 6: Job Description Updates

  • Work with HR to update job descriptions with security responsibilities
  • Update recruitment templates and job postings
  • Update performance evaluation templates with security KPIs
  • Update onboarding materials with security role expectations
  • Create security role competency framework

Week 7: Training and Awareness

  • Develop role-specific security training modules
  • Train managers on their security responsibilities
  • Train data owners and system owners on their specific responsibilities
  • Train end users on their general security responsibilities
  • Train security team members on their specialized responsibilities
  • Deliver initial security awareness program for all employees

Week 8: Integration with HR and Operations

  • Integrate security responsibilities into HR processes (hiring, onboarding, performance review, promotion, termination)
  • Integrate security responsibilities into operational processes (change management, project management, procurement)
  • Update employment contracts and terms with security clauses (reference A.6.2)
  • Update contractor and vendor agreements with security role requirements
  • Establish security role assignment process for new hires

Deliverables: Communication materials, Updated job descriptions, Training completion records, HR integration, Updated contracts

Phase 3: Governance Activation (Weeks 9–12)

Week 9: Security Committee Activation

  • Convene the first Security Committee meeting
  • Define meeting cadence, agenda, and governance processes
  • Approve the Security Governance Charter
  • Approve the Information Security Roles and Responsibilities document
  • Define security decision-making processes and escalation paths
  • Establish security reporting to the Board or executive leadership

Week 10: Role Assignment and Accountability

  • Formally assign security roles to specific individuals
  • Issue role assignment letters or documentation
  • Publish the organization-wide security roles and responsibilities matrix
  • Announce the security governance structure to the organization
  • Establish role-specific communication channels (e.g., security liaisons for each business unit)
  • Create security role directory or contact list

Week 11: Operationalization

  • Begin operating under new security governance structure
  • Security Committee meets regularly
  • Security roles begin performing their defined responsibilities
  • Security reporting begins flowing through defined channels
  • Security decisions follow defined authority levels
  • Escalation paths are tested and validated

Week 12: Baseline Assessment

  • Assess initial effectiveness of new security governance
  • Collect feedback from role holders on clarity and feasibility
  • Identify any gaps or issues in the new structure
  • Measure baseline security metrics (incident reporting, compliance, awareness)
  • Document lessons learned

Deliverables: Security Committee operational, Roles assigned, Governance active, Baseline assessment

Phase 4: Optimization (Weeks 13–16)

Week 13-14: Metrics and Monitoring

  • Define and implement KPIs for security roles and governance (see Section 13)
  • Implement tracking of security role performance
  • Monitor security governance effectiveness
  • Conduct first formal review of security role performance

Week 15-16: Continuous Improvement

  • Update roles and responsibilities based on feedback and changing needs
  • Refine governance processes based on experience
  • Enhance training based on observed gaps
  • Update documentation and communication materials
  • Plan for annual review and refresh cycle

Deliverables: KPI tracking, Performance reviews, Updated governance, Annual review plan

Maturity Model

LevelDescriptionTypical Timeline
1, Ad-hocNo formal security roles; security is an afterthought or assigned informally to whoever is availablePre-implementation
2, ManagedBasic security role defined (e.g., "IT Manager handles security"); informal responsibilities understoodWeeks 1–4
3, DefinedFormal security roles, responsibilities, and governance documented; roles assigned to individuals; communication completedWeeks 5–16
4, Quantitatively ManagedSecurity role performance measured; KPIs tracked; security governance actively managed; role effectiveness evaluatedUsually 1–2 years
5, OptimizingSecurity roles continuously refined; roles adapt to changing threats and business; security culture embedded; proactive role evolutionOngoing

Detailed Implementation Guidance

The Security Governance Structure

Organizational Models for Security

Model 1: Centralized Security (Recommended for Most Organizations)

Board of Directors
    └── Security Committee (or Audit Committee with security oversight)
        └── CISO (reports to CEO/COO/CIO)
            ├── Security Operations (SOC, Incident Response)
            ├── Governance, Risk & Compliance (GRC)
            ├── Security Architecture & Engineering
            ├── Privacy and Compliance
            └── Security Awareness & Training

Characteristics:

  • Single CISO with unified security team
  • Consistent security policies and standards across the organization
  • Centralized security decision-making
  • Efficient resource allocation
  • Clear accountability chain

Best for: Small to medium organizations, organizations with unified IT, organizations seeking strong security governance

Model 2: Decentralized Security (Federal Model)

Board of Directors
    └── Security Committee
        ├── CISO (Corporate/Governance)
        ├── Business Unit 1 Security Lead (reports to BU Head + dotted line to CISO)
        ├── Business Unit 2 Security Lead (reports to BU Head + dotted line to CISO)
        └── Business Unit 3 Security Lead (reports to BU Head + dotted line to CISO)

Characteristics:

  • Security roles embedded in business units
  • Business unit security leads report to business leaders with dotted-line to CISO
  • Business unit-tailored security practices
  • Distributed security decision-making with governance oversight
  • Stronger business alignment but potential inconsistency

Best for: Large enterprises with independent business units, conglomerates, organizations with diverse risk profiles

Model 3: Hybrid Security (Hub-and-Spoke)

Board of Directors
    └── Security Committee
        └── CISO (Central)
            ├── Security Operations Center (Central)
            ├── GRC Team (Central)
            ├── Security Architecture (Central)
            └── Security Liaisons (Embedded in each BU/Department)

Characteristics:

  • Central security functions for operations, compliance, and architecture
  • Embedded security liaisons in business units for local coordination
  • Liaisons do not have full security authority but serve as communication and coordination points
  • Central team maintains standards; local liaisons implement them

Best for: Medium to large organizations with multiple departments, matrix organizations, organizations transitioning from decentralized to centralized

Model 4: Outsourced Security (Virtual CISO)

Board of Directors
    └── Security Committee
        └── Virtual CISO (External consultant, part-time)
            ├── Managed Security Service Provider (MSSP) — SOC
            ├── External Security Consultant — Policy and Compliance
            ├── External Penetration Testing Provider
            └── Internal IT Manager (Security coordination)

Characteristics:

  • Security leadership is external or part-time
  • Security operations may be fully outsourced to MSSP
  • Internal staff handle coordination and communication
  • Lower cost but potentially less organizational integration

Best for: Small organizations, startups, organizations with limited security budget, organizations with simple security requirements

Detailed Role Definitions

Executive Security Roles

Chief Information Security Officer (CISO)

  • Accountability: Overall information security program effectiveness
  • Responsibilities:
    • Develop and maintain the information security strategy and program
    • Define security policies, standards, and guidelines
    • Report security status, risk, and incidents to the Board and executive leadership
    • Manage the security budget and resources
    • Lead the security team and oversee security operations
    • Ensure regulatory compliance and manage security audits
    • Serve as the primary security liaison with external stakeholders (regulators, customers, partners)
    • Drive security culture and awareness across the organization
    • Advise risk owners on high-risk decisions and exceptions (residual risk is accepted by the risk owner)
  • Authority: Can approve topic-specific security policies, the security budget within delegated limits, and incident response decisions
  • Reporting: Typically reports to CEO, COO, or CIO; ideally reports to CEO for independence
  • Key Performance Indicators:
    • Security incident frequency and severity
    • Compliance audit results (findings, certifications)
    • Security risk reduction (risk score trend)
    • Security awareness score
    • Mean time to detect and respond to incidents
    • Security budget use and ROI

Chief Information Officer (CIO) / Chief Technology Officer (CTO)

  • Accountability: Security of IT infrastructure and technology systems
  • Responsibilities:
    • Ensure security is integrated into IT strategy and operations
    • Allocate IT resources for security controls and tools
    • Ensure secure development practices in technology projects
    • Manage IT security architecture and engineering
    • Coordinate with CISO on technology security initiatives
  • Authority: Can approve IT security investments, architecture decisions, and technology security standards
  • Reporting: Reports to CEO or COO
  • Key Performance Indicators:
    • IT security vulnerability remediation time
    • Secure development lifecycle adoption
    • IT security incident rate
    • IT security compliance rate

Chief Executive Officer (CEO) / Managing Director

  • Accountability: Ultimate accountability for organizational security (as the highest executive)
  • Responsibilities:
    • Approve the information security strategy and policy
    • Allocate resources for the security program
    • Support security culture from the top
    • Receive and act on security risk reports from the CISO
    • Ensure security is considered in business decisions
  • Authority: Ultimate authority for security strategy, budget, and critical decisions
  • Reporting: Reports to Board of Directors
  • Key Performance Indicators:
    • Security posture as reported by CISO
    • Board-level security risk exposure
    • Security investment as percentage of IT budget
    • Security culture index

Board of Directors / Security Committee

  • Accountability: Governance oversight of security risk
  • Responsibilities:
    • Oversee the organization's security risk management
    • Review and approve security strategy and policy
    • Ensure adequate resources for security
    • Review security incident reports and risk assessments
    • Hold management accountable for security performance
  • Authority: Can approve security strategy, mandate security investments, and hold executives accountable
  • Key Performance Indicators:
    • Security risk exposure trend
    • Number of critical security incidents
    • Regulatory compliance status
    • Security audit results

Security Function Roles

Security Manager / Security Lead

  • Accountability: Day-to-day security program management
  • Responsibilities:
    • Implement and manage security policies, procedures, and controls
    • Coordinate security activities across departments
    • Manage security projects and initiatives
    • Conduct security risk assessments and manage risk register
    • Manage security vendor relationships and contracts
    • Track security metrics and prepare reports
    • Coordinate security audits and compliance assessments
    • Manage security documentation and evidence
  • Authority: Can approve security procedures, low-risk exceptions, and security tool configurations
  • Reporting: Reports to CISO
  • Key Performance Indicators:
    • Security control implementation rate
    • Risk treatment completion rate
    • Audit finding closure rate
    • Security project delivery on time and budget
    • Policy compliance rate

Security Operations Center (SOC) Analyst / Security Monitoring Analyst

  • Accountability: Detection and initial response to security events
  • Responsibilities:
    • Monitor security alerts and events 24/7 (or during assigned shifts)
    • Triage security alerts and classify severity
    • Initiate incident response for confirmed security events
    • Conduct initial investigation and containment
    • Maintain security monitoring tools and SIEM
    • Generate security event reports and dashboards
    • Escalate critical events to incident response team
  • Authority: Can initiate incident response, request system isolation, and escalate alerts
  • Reporting: Reports to SOC Manager or Security Manager
  • Key Performance Indicators:
    • Mean time to detect (MTTD)
    • Mean time to respond (MTTR), initial response
    • Alert triage accuracy (false positive rate)
    • Incident escalation rate
    • Monitoring coverage (percentage of systems monitored)

Incident Response Manager / Lead

  • Accountability: Effective management and resolution of security incidents
  • Responsibilities:
    • Lead incident response activities from detection to closure
    • Coordinate cross-functional incident response teams
    • Manage incident communication (internal, external, regulatory)
    • Conduct post-incident reviews and root cause analysis
    • Maintain incident response plans and playbooks
    • Conduct incident response drills and exercises
    • Report incident metrics and trends to leadership
  • Authority: Can declare incident severity, authorize containment actions, and approve incident communications
  • Reporting: Reports to CISO or Security Manager
  • Key Performance Indicators:
    • Mean time to contain (MTTC)
    • Mean time to recover (MTTR)
    • Incident resolution quality (repeat incidents)
    • Communication timeliness
    • Lessons learned implementation rate

Security Architect

  • Accountability: Security architecture and design integrity
  • Responsibilities:
    • Design security architecture for systems, networks, and applications
    • Define security standards and technical controls
    • Review new systems and changes for security compliance
    • Conduct security architecture reviews and threat modeling
    • Evaluate and recommend security technologies
    • Ensure security is built into system design (security by design)
    • Maintain security architecture documentation
  • Authority: Can approve security architecture designs, recommend security technologies, and reject insecure designs
  • Reporting: Reports to CISO or Security Manager
  • Key Performance Indicators:
    • Security architecture review completion rate
    • Security design defects found in production
    • Security architecture alignment with standards
    • New technology security evaluation turnaround time
    • Security by design adoption rate

Security Engineer / Security Administrator

  • Accountability: Implementation and maintenance of security controls
  • Responsibilities:
    • Implement and configure security tools and technologies (firewall, IDS/IPS, SIEM, DLP, encryption)
    • Maintain security infrastructure and ensure availability
    • Deploy security patches and updates
    • Manage security certificates and keys
    • Configure and maintain access controls
    • Implement security monitoring and logging
    • Support security operations and incident response with technical expertise
  • Authority: Can configure security tools, implement approved changes, and recommend security configurations
  • Reporting: Reports to Security Manager or Security Architect
  • Key Performance Indicators:
    • Security tool availability and uptime
    • Patch deployment timeliness
    • Security configuration compliance rate
    • Security infrastructure incident rate
    • Change implementation success rate

Governance, Risk, and Compliance (GRC) Analyst / Compliance Officer

  • Accountability: Regulatory compliance and security governance effectiveness
  • Responsibilities:
    • Manage security compliance with regulatory requirements (RBI, SEBI, IRDAI, DPDP Act, PCI DSS, ISO 27001)
    • Conduct compliance assessments and audits
    • Maintain compliance documentation and evidence
    • Track and report compliance status
    • Manage regulatory relationships and communications
    • Coordinate external audits and assessments
    • Maintain security policies, standards, and procedures
    • Track and manage security findings and remediation
  • Authority: Can identify compliance gaps, recommend remediation, and escalate compliance risks
  • Reporting: Reports to CISO or directly to Compliance Head
  • Key Performance Indicators:
    • Compliance audit findings (number, severity, trend)
    • Compliance remediation completion rate
    • Regulatory communication timeliness
    • Policy review and update cycle time
    • Evidence completeness and availability

Privacy Officer / Data Protection Officer (DPO)

  • Accountability: Data privacy and protection compliance
  • Responsibilities:
    • Ensure compliance with data protection laws (DPDP Act 2023, GDPR if applicable)
    • Manage data principal rights requests and grievances (DPDP ss.11–14)
    • Conduct privacy impact assessments (PIAs)
    • Maintain records of processing (a GDPR ROPA duty; under DPDP, keep the records needed to show compliance)
    • Serve as point of contact for data protection authorities
    • Ensure privacy by design in systems and processes
    • Manage data breach notification processes for personal data
    • Develop and maintain privacy policies and notices
  • Authority: Can approve privacy policies, authorize data processing activities, and escalate privacy risks
  • Reporting: For a Significant Data Fiduciary, the DPO is based in India and answerable to the Board (DPDP s.10(2)); under GDPR the DPO reports to the highest management level (Art. 38(3)). Avoid placing the DPO under the CISO, which creates an independence conflict. Other fiduciaries need a published contact person (s.8(9)) rather than a DPO.
  • Key Performance Indicators:
    • Data principal request response time
    • Privacy impact assessment completion rate
    • Data breach notification timeliness
    • Privacy audit findings
    • Privacy training completion rate

Business and Data Roles

Data Owner

  • Accountability: Security, accuracy, and appropriate use of a specific data asset
  • Responsibilities:
    • Classify data according to the organization's classification scheme
    • Define and approve access to their data assets
    • Ensure data is protected according to its classification
    • Approve data sharing and data processing agreements
    • Review and approve data access requests
    • Ensure data quality and integrity
    • Monitor data usage and compliance
    • Approve data retention and destruction schedules
  • Authority: Can approve data access, data classification, and data sharing decisions for their data assets
  • Reporting: Reports to business leadership (e.g., Department Head, Business Unit Head)
  • Key Performance Indicators:
    • Data classification coverage (percentage of data classified)
    • Data access review completion rate
    • Data quality metrics
    • Data incident rate for their data assets
    • Data sharing compliance rate

System Owner

  • Accountability: Security, availability, and compliance of a specific information system
  • Responsibilities:
    • Ensure the system is secure and compliant with policies and standards
    • Approve system access and changes
    • Manage system risk register and treatment
    • Ensure system is maintained and patched
    • Approve system changes that affect security
    • Monitor system security status and performance
    • Ensure system documentation is current
    • Coordinate with security team on system security matters
  • Authority: Can approve system changes, system access, and system risk acceptance for their systems
  • Reporting: Reports to IT leadership or business leadership (depending on the system)
  • Key Performance Indicators:
    • System vulnerability remediation time
    • System availability and uptime
    • System security audit findings
    • System change approval turnaround time
    • System risk score trend

Business Unit Head / Department Head

  • Accountability: Security of their business unit's information and operations
  • Responsibilities:
    • Ensure business unit complies with security policies and standards
    • Appoint and support data owners and system owners within their unit
    • Allocate resources for security within their unit
    • Ensure staff in their unit are trained on security responsibilities
    • Report security incidents and risks within their unit
    • Participate in security governance and decision-making
    • Integrate security into business processes and projects
  • Authority: Can approve business unit security resources, accept business unit risk, and enforce security compliance within their unit
  • Reporting: Reports to executive leadership
  • Key Performance Indicators:
    • Business unit security compliance rate
    • Business unit security incident rate
    • Business unit security training completion rate
    • Business unit audit findings
    • Security integration into business processes

Project Manager / Product Owner

  • Accountability: Security of project deliverables and product features
  • Responsibilities:
    • Ensure security requirements are included in project/product planning
    • Allocate project resources for security activities
    • Ensure security reviews are conducted at appropriate project gates
    • Manage security risks within the project scope
    • Ensure project deliverables meet security standards
    • Coordinate with security team on project security matters
  • Authority: Can approve project security resources, escalate project security risks to the designated risk owner, and mandate security activities within their project
  • Reporting: Reports to business or IT leadership
  • Key Performance Indicators:
    • Security requirements included in projects (percentage)
    • Security review completion at project gates
    • Security defects in project deliverables
    • Project security risk closure rate
    • Security training completion by project team

IT and Technical Roles

System Administrator

  • Accountability: Secure operation and maintenance of systems
  • Responsibilities:
    • Securely configure, maintain, and patch systems
    • Manage user accounts and access permissions on systems
    • Monitor system logs and security events
    • Implement system-level security controls
    • Report system security incidents and vulnerabilities
    • Ensure system backups and recovery capabilities
    • Follow change management procedures for system changes
  • Authority: Can manage system configurations, user accounts, and implement approved security changes
  • Reporting: Reports to IT Manager or Infrastructure Lead
  • Key Performance Indicators:
    • System patching compliance
    • System configuration compliance with security standards
    • System uptime and availability
    • System security incident rate
    • Change management compliance

Network Administrator

  • Accountability: Secure operation of network infrastructure
  • Responsibilities:
    • Securely configure and maintain network devices (firewalls, routers, switches)
    • Manage network segmentation and access controls
    • Monitor network traffic for security threats
    • Implement network-level security controls (VPN, IDS/IPS, DLP)
    • Maintain network security documentation
    • Respond to network security incidents
  • Authority: Can manage network configurations, implement approved network security changes
  • Reporting: Reports to IT Manager or Infrastructure Lead
  • Key Performance Indicators:
    • Network security configuration compliance
    • Network security incident rate
    • Network vulnerability remediation time
    • Network monitoring coverage
    • Network availability and uptime

Database Administrator (DBA)

  • Accountability: Secure operation of database systems and data integrity
  • Responsibilities:
    • Securely configure and maintain database systems
    • Manage database access controls and permissions
    • Implement database encryption and security controls
    • Monitor database access and security events
    • Ensure database backup and recovery security
    • Report database security incidents and vulnerabilities
    • Manage database patching and updates
  • Authority: Can manage database configurations, access controls, and implement approved security changes
  • Reporting: Reports to IT Manager or Data Platform Lead
  • Key Performance Indicators:
    • Database security configuration compliance
    • Database access control accuracy
    • Database patching compliance
    • Database security incident rate
    • Database availability and uptime

Application Developer / Software Engineer

  • Accountability: Secure coding and application security
  • Responsibilities:
    • Follow secure coding practices and standards
    • Conduct security testing of their code (SAST, DAST, code review)
    • Report and fix security vulnerabilities in their applications
    • Participate in security training and secure development education
    • Follow the secure development lifecycle (SDLC)
    • Use approved security libraries and frameworks
    • Report security incidents related to their applications
  • Authority: Can fix security vulnerabilities in their code, implement approved security features
  • Reporting: Reports to Development Manager or Engineering Lead
  • Key Performance Indicators:
    • Security vulnerabilities in released code
    • Secure code review completion rate
    • Security testing completion rate
    • Security training completion rate
    • Time to fix security vulnerabilities

DevOps Engineer / Cloud Engineer

  • Accountability: Security of infrastructure as code and deployment pipelines
  • Responsibilities:
    • Implement security in CI/CD pipelines (DevSecOps)
    • Securely configure cloud infrastructure and containers
    • Manage infrastructure security controls and policies
    • Ensure secure deployment practices
    • Monitor infrastructure security and compliance
    • Respond to infrastructure security incidents
    • Implement security automation and guardrails
  • Authority: Can manage infrastructure security configurations, implement approved security automation
  • Reporting: Reports to DevOps Lead or Cloud Infrastructure Lead
  • Key Performance Indicators:
    • Infrastructure security compliance (IaC scanning)
    • Security gate pass rate in CI/CD
    • Container image security scan pass rate
    • Cloud security configuration compliance
    • Infrastructure security incident rate

Support and Functional Roles

Human Resources (HR)

  • Accountability: Security of personnel processes and employee data
  • Responsibilities:
    • Include security responsibilities in job descriptions and contracts
    • Conduct security screening and background checks
    • Deliver security onboarding and awareness training
    • Manage security aspects of termination and role changes
    • Enforce security consequences through disciplinary process
    • Maintain employee security training records
    • Report insider threats and security concerns related to personnel
  • Key Performance Indicators:
    • Security screening completion rate
    • Security training completion rate
    • Security clause inclusion in contracts
    • Termination security process completion rate
    • Employee security incident rate

Legal / Compliance

  • Accountability: Legal and regulatory compliance of security practices
  • Responsibilities:
    • Review security policies and contracts for legal compliance
    • Manage legal aspects of security incidents (breach notification, litigation)
    • Ensure security practices comply with applicable laws and regulations
    • Review and approve security-related contracts and agreements
    • Manage regulatory relationships and communications
    • Advise on legal implications of security decisions
  • Key Performance Indicators:
    • Legal review completion for security policies
    • Regulatory compliance status
    • Security contract review turnaround time
    • Legal risk from security incidents
    • Regulatory communication timeliness

Finance

  • Accountability: Security of financial data and processes
  • Responsibilities:
    • Protect financial data and systems
    • Ensure financial processes comply with security policies
    • Allocate and manage security budget
    • Report financial security incidents (fraud, financial data breaches)
    • Ensure financial systems meet security standards
  • Key Performance Indicators:
    • Financial system security compliance
    • Financial data security incident rate
    • Security budget use
    • Fraud detection rate
    • Financial audit security findings

Procurement / Vendor Management

  • Accountability: Security of third-party relationships and supply chain
  • Responsibilities:
    • Include security requirements in procurement processes and contracts
    • Assess vendor security posture before engagement
    • Monitor vendor security compliance throughout the relationship
    • Manage security aspects of vendor contracts and SLAs
    • Report third-party security incidents
  • Key Performance Indicators:
    • Vendor security assessment completion rate
    • Security clause inclusion in contracts
    • Vendor security incident rate
    • Third-party risk score trend
    • Vendor security audit findings

Facilities / Physical Security

  • Accountability: Physical security of facilities and assets
  • Responsibilities:
    • Secure physical access to facilities and sensitive areas
    • Manage physical security controls (access cards, CCTV, guards)
    • Protect physical assets (servers, workstations, documents)
    • Respond to physical security incidents
    • Coordinate physical security with information security
  • Key Performance Indicators:
    • Physical security incident rate
    • Physical access control compliance
    • Asset protection compliance
    • Physical security audit findings
    • CCTV and alarm coverage

End-User Roles

All Employees

  • Accountability: Secure handling of information in their daily work
  • Responsibilities:
    • Follow security policies, procedures, and standards
    • Protect their accounts and credentials (strong passwords, MFA, no sharing)
    • Report security incidents, suspicious activities, and security concerns
    • Complete required security awareness training
    • Handle information according to its classification
    • Use information systems and assets only for authorized purposes
    • Secure their workspace and devices (lock screens, secure devices when away)
    • Report lost or stolen devices immediately
    • Follow acceptable use policies for internet, email, and social media
    • Not install unauthorized software or hardware
    • Verify identity before sharing information or providing access
  • Key Performance Indicators:
    • Security training completion rate
    • Phishing simulation click rate
    • Security incident reporting rate
    • Policy violation rate
    • Security awareness quiz score

Contractors / Temporary Staff / Interns

  • Accountability: Same as employees, but with additional restrictions
  • Responsibilities:
    • Same as all employees, plus:
    • Comply with additional security restrictions for non-permanent staff
    • Use only authorized access and systems for their specific assignment
    • Return all assets and access upon contract completion
    • Not access systems or data beyond their assigned scope
    • Follow enhanced monitoring requirements
  • Key Performance Indicators:
    • Contractor security training completion rate
    • Contractor security incident rate
    • Asset return completion rate
    • Access revocation completion rate
    • Contractor policy violation rate

The RACI Matrix for Security Activities

A RACI matrix should be created for every significant security activity, defining who is:

  • R: Responsible (does the work)
  • A: Accountable (owns the outcome, answers for results)
  • C: Consulted (provides input, two-way communication)
  • I: Informed (receives updates, one-way communication)

Sample RACI Matrix for Key Security Activities:

Security ActivityCISOSecurity ManagerSystem OwnerIT ManagerHRLegalEnd UserBusiness Unit Head
Security Policy DevelopmentARCCCCIC
Risk AssessmentARCCIIIC
Access ControlARRCIIIC
Incident ResponseARCRCCIC
Security Awareness TrainingARIIRIRC
Vulnerability ManagementARCRIIII
Security AuditARCCICIC
Data ClassificationCCRIICIA
Change Management Security ReviewARCRIIIC
Vendor Security AssessmentARCCICIC
Business ContinuityCCRCCCIA
Compliance ReportingARCIICIC
Physical SecurityCCICICIA
Security BudgetARCCIIIC
Penetration TestingARCRIIIC
Backup and RecoveryACRRIIIC
Security ArchitectureARCRIIIC
Privacy ComplianceACRICCIC
Incident ReportingCRIIIIRI
Security MetricsARCCIIIC

Security Responsibilities in Job Descriptions

Every job description should include a security responsibilities section. Examples:

For a Software Developer:

Security Responsibilities:
- Follow secure coding practices and standards defined by the Security Team
- Participate in security code reviews and security testing (SAST, DAST)
- Report and remediate security vulnerabilities in your code within defined SLAs
- Complete annual secure development training
- Use only approved security libraries and frameworks
- Report security incidents related to your applications immediately
- Ensure your development environment meets security standards

For a Sales Representative:

Security Responsibilities:
- Protect customer data and confidential business information
- Use only approved tools and channels for customer communication
- Follow data classification and handling procedures for all information
- Report lost or stolen devices immediately
- Complete annual security awareness training
- Verify customer identity before sharing sensitive information
- Follow acceptable use policies for email and internet
- Report suspicious emails or phishing attempts to the Security Team

For a Finance Manager:

Security Responsibilities:
- Protect financial data and ensure access is limited to authorized personnel
- Follow security controls for financial systems (MFA, secure access, logging)
- Report financial security incidents (fraud, unauthorized transactions) immediately
- Ensure financial processes comply with security policies
- Complete annual security awareness training and role-specific security training
- Participate in financial system security audits
- Approve access to financial data and systems within your authority
- Ensure backup and recovery of financial data

For a System Administrator:

Security Responsibilities:
- Securely configure, patch, and maintain systems under your responsibility
- Manage user access accounts and permissions according to least privilege
- Monitor system security logs and report anomalies to the Security Team
- Implement approved security controls on systems
- Follow change management procedures for all system changes
- Ensure system backups are secure and tested regularly
- Report security vulnerabilities and incidents immediately
- Complete technical security training annually
- Conduct quarterly access reviews for systems you administer

Security Committee Governance

Security Committee Charter Template:

Template

Security Committee Meeting Agenda Template:

Template

Communication of Security Responsibilities

Communication Channels:

  • Job descriptions and contracts: Formal documentation of responsibilities
  • Employee handbook: General security responsibilities for all employees
  • Onboarding briefing: Security responsibilities introduced to new hires
  • Annual security awareness training: Refresher on responsibilities
  • Security intranet / knowledge base: Accessible reference for all security roles and responsibilities
  • Security newsletter / bulletin: Regular reminders and updates
  • Manager briefings: Department-specific security responsibilities communicated by managers
  • Posters and signage: Visual reminders in common areas
  • Security role contact cards: Wallet cards with key security contacts and responsibilities
  • Email campaigns: Targeted communication on specific responsibilities (e.g., "Your Role in Data Protection")
  • Team meetings: Regular discussion of security responsibilities in team meetings
  • Security town halls: Organization-wide communication on security matters

Communication Frequency:

  • New hire: Security responsibilities communicated during onboarding (within first week)
  • Role change: Security responsibilities communicated when an employee changes roles (within one week of change)
  • Annual: Security responsibilities refresher communicated annually (during annual security training)
  • Policy change: Security responsibilities communicated whenever policies change (within one week of change)
  • Incident-triggered: Specific responsibilities communicated after security incidents (within 48 hours of incident)
  • Continuous: Security responsibilities reinforced through ongoing awareness program

Tools, Technologies, and Solutions

GRC and Governance Platforms

ToolBest ForPricing model
ServiceNow GRCEnterprise governance, risk, and compliance managementEnterprise pricing
RSA ArcherEnterprise GRC, risk management, complianceEnterprise pricing
MetricStreamEnterprise GRC, audit managementEnterprise pricing
SAP GRCSAP-integrated governance and riskEnterprise pricing
StandardFusionSMB GRC, compliance managementCommercial
HyperproofCompliance operations, evidence managementCommercial
Draw.io (diagrams.net)Free diagramming for governance structuresFree
Google Docs / Microsoft 365Document collaboration for policies and chartersFree / Included in subscription

HR and Talent Management Tools for Security Roles

ToolBest ForPricing model
WorkdayEnterprise HR, talent management, role managementEnterprise pricing
SAP SuccessFactorsEnterprise HR, performance managementEnterprise pricing
Oracle HCMEnterprise HR, talent managementEnterprise pricing

Indian Security Governance and Advisory Services

VendorOfferingWebsite
SingahiSecurity governance setup, CISO advisory, role definition, RACI design, security committee setup/
NASSCOMIndustry security guidance, CISO forumshttps://www.nasscom.in
CERT-InGovernment security guidance, incident responsehttps://www.cert-in.org.in
ISO 27001 Certification BodiesTUV, BSI, DNV, SGS, Bureau Veritas: certification audits only (accredited certification bodies may not consult on the ISMS they certify, ISO/IEC 17021-1)Multiple

Policy and Procedure Templates

Information Security Roles and Responsibilities Policy (Template)

Template

Job Description Security Addendum (Template)

Template


Risk Assessment and Treatment

Risk Assessment for Security Roles and Responsibilities

Risk IDRisk DescriptionLikelihoodImpactRisk LevelMitigation
R-001No CISO or senior security leader appointedMediumCriticalHighAppoint CISO or virtual CISO; define in governance charter
R-002Security responsibilities not defined in job descriptionsHighHighHighUpdate all job descriptions with security addenda; HR integration
R-003Security roles overlap causing confusion or gapsMediumMediumMediumRACI matrix; role definition; regular review
R-004Security roles not communicated to employeesMediumHighHighOnboarding briefing; annual training; intranet documentation
R-005Security governance structure not establishedMediumCriticalHighEstablish Security Committee; define governance charter
R-006No security reporting to Board/executivesMediumHighHighBoard reporting mechanism; quarterly security updates
R-007Third-party security roles not definedHighHighHighContract security clauses; SLA security requirements; vendor accountability
R-008Security role holders lack skills/competencyMediumHighHighCompetency framework; training; certification requirements
R-009Security roles not reviewed after organizational changeHighMediumMediumChange-triggered review process; annual review cycle
R-010Security responsibilities not enforcedMediumHighHighPerformance evaluation integration; disciplinary process; management accountability
R-011Security roles conflict with business objectivesLowMediumLowSecurity governance committee; business alignment; risk-based decisions
R-012Too many security roles causing bureaucracyLowLowLowLean governance design; automation; clear RACI
R-013Outsourced security roles lack accountabilityMediumHighHighContractual accountability; SLA monitoring; governance oversight
R-014Security role turnover causes knowledge lossMediumMediumMediumDocumentation; knowledge transfer; cross-training; role continuity planning
R-015Small organization cannot afford dedicated security rolesHighMediumMediumVirtual CISO; shared responsibility model; outsourced security; risk-based prioritization

Risk Treatment Options

RiskTreatmentResidual Risk
R-001Appoint CISO/vCISO; governance charterLow
R-002HR integration; job description update; onboarding processLow
R-003RACI matrix; role clarity; regular reviewLow
R-004Communication plan; onboarding; annual training; intranetLow
R-005Security Committee; governance charter; executive approvalLow
R-006Board reporting; quarterly updates; executive dashboardLow
R-007Vendor security clauses; SLA requirements; vendor managementLow
R-008Competency framework; training budget; certification supportLow
R-009Organizational change trigger; annual review; HR notificationLow
R-010Performance evaluation integration; management accountability; consequencesLow
R-011Security governance; business alignment; risk-based approachLow
R-012Lean design; automation; clear authority levelsLow
R-013Contractual accountability; SLA monitoring; governance reviewLow
R-014Documentation; cross-training; succession planning; knowledge baseLow
R-015Virtual CISO; shared roles; outsourcing; phased approachLow

Audit and Compliance Checklist

Pre-Audit Self-Assessment

#QuestionEvidenceStatus
1Are information security roles formally defined and documented?Role definitions document☐
2Is there a designated CISO or equivalent security leader?Appointment letter, org chart☐
3Are security responsibilities included in job descriptions?Job descriptions, HR records☐
4Are security responsibilities included in employment contracts?Contracts, terms of employment☐
5Are security responsibilities communicated to all employees?Training records, onboarding records☐
6Is there a security governance structure (committee, board reporting)?Governance charter, meeting minutes☐
7Is there a Security Committee with defined membership and responsibilities?Committee charter, membership list☐
8Does the Security Committee meet regularly?Meeting minutes, attendance records☐
9Does security report to the Board or executive leadership?Board reports, meeting minutes☐
10Are security responsibilities allocated according to the organization's needs?Roles matrix, needs assessment☐
11Is there a RACI matrix for security activities?RACI matrix☐
12Are third-party security roles defined in contracts?Vendor contracts, SLAs☐
13Are security roles reviewed and updated regularly?Review records, updated documents☐
14Are security role holders competent to perform their responsibilities?Competency records, training records, certifications☐
15Are security responsibilities enforced through performance evaluations?Performance evaluation records☐
16Are security responsibilities communicated to new hires during onboarding?Onboarding materials, training records☐
17Are security responsibilities communicated upon role change?Role change documentation, communication records☐
18Is there a process for assigning security roles to new systems or data?Role assignment process, system records☐
19Are security responsibilities included in the annual security awareness program?Training program, attendance records☐
20Are security roles and responsibilities accessible to all employees?Intranet, knowledge base, documentation☐
21Are there defined data owners for information assets?Data owner register, asset inventory☐
22Are there defined system owners for information systems?System owner register, system inventory☐
23Are security responsibilities for outsourced functions defined?Outsourcing contracts, SLA security clauses☐
24Are security role assignments documented and approved?Assignment records, approval documentation☐
25Are there defined incident response roles?Incident response plan, role definitions☐
26Are there defined risk management roles?Risk management procedure, role definitions☐
27Are there defined compliance roles?Compliance program, role definitions☐
28Are security responsibilities for senior management defined?Management responsibility document, governance charter☐
29Are security responsibilities for Board members defined?Board charter, governance documents☐
30Are security role metrics tracked and reported?Metrics dashboard, reports☐

Auditor Interview Questions

Be prepared to answer:

  1. "Who is responsible for information security in your organization?"
  2. "Can you show me the documented security roles and responsibilities?"
  3. "Are security responsibilities included in job descriptions?"
  4. "How do you ensure employees understand their security responsibilities?"
  5. "Is there a security governance structure? Can you show me the charter?"
  6. "Does security report to the Board? How often?"
  7. "How do you handle security roles for third-party vendors?"
  8. "Are security roles reviewed and updated? How often?"
  9. "How do you verify that security role holders are competent?"
  10. "Are security responsibilities part of performance evaluations?"

Common Audit Findings and How to Avoid Them

FindingCausePrevention
"No one assigned responsibility for the ISMS" (clause 5.3)Responsibility and authority not assigned or communicatedAssign an ISMS owner (CISO, vCISO or other); document in governance charter
"Security responsibilities not in job descriptions"HR not integratedUpdate job descriptions; HR policy integration
"No security governance structure"No committee or board reportingEstablish Security Committee; define charter; board reporting
"Employees don't know their security responsibilities"No communication or trainingOnboarding briefing; annual training; intranet; manager communication
"No data owners assigned"No ownership processData owner register; assignment process; system inventory
"Third-party security roles not defined"Weak vendor managementContract security clauses; SLA requirements; vendor accountability
"Security roles not reviewed after reorganization"No change-triggered reviewOrganizational change notification; role review trigger; annual review
"Security responsibilities not enforced"No consequencesPerformance evaluation integration; disciplinary process; management accountability
"No RACI matrix for security activities"No role clarityRACI matrix for key activities; role definition; communication
"Security Committee does not meet regularly"No governance disciplineMeeting cadence; calendar; minutes; attendance tracking

Metrics and KPIs

Figure · Measures

The measures that show A.5.2 is working

  • Security Role Definition Coverage100%Quarterly
  • Job Description Security Inclusion100%Quarterly
  • Contract Security Clause Inclusion100%Quarterly
  • Security Responsibility Communication Rate100%Quarterly
  • Onboarding Security Briefing Completion100%Monthly
Targets and reporting cadence as defined in the table below, where the formula for each is given.

Process Metrics

MetricFormulaTargetFrequency
Security Role Definition Coverage(# of roles with defined security responsibilities / # of total roles) × 100100%Quarterly
Job Description Security Inclusion(# of job descriptions with security responsibilities / # of total job descriptions) × 100100%Quarterly
Contract Security Clause Inclusion(# of employment contracts with security clauses / # of total contracts) × 100100%Quarterly
Security Responsibility Communication Rate(# of employees who received security responsibility communication / # of total employees) × 100100%Quarterly
Onboarding Security Briefing Completion(# of new hires with security briefing / # of total new hires) × 100100%Monthly
Annual Security Training Completion(# of employees who completed annual security training / # of total employees) × 100100%Quarterly
Security Committee Meeting FrequencyNumber of meetings held / Number of meetings planned100%Quarterly
Board Security Reporting FrequencyNumber of Board security reports delivered / Number planned100%Quarterly
Security Role Review CompletionSecurity roles reviewed in the last 12 months100%Annual
Data Owner Assignment Coverage(# of data assets with assigned owner / # of total data assets) × 100100%Quarterly
System Owner Assignment Coverage(# of systems with assigned owner / # of total systems) × 100100%Quarterly
Third-Party Security Role Definition(# of vendor contracts with defined security roles / # of total vendor contracts) × 100100%Quarterly
Security Role Competency Assessment(# of security role holders with competency assessment / # of total security role holders) × 100100%Annual
Security Role Performance Evaluation(# of employees with security responsibilities in performance evaluation / # of total employees with security responsibilities) × 100100%Annual
Security Role Assignment Approval(# of security role assignments with formal approval / # of total assignments) × 100100%Quarterly

Outcome Metrics

MetricFormulaTargetFrequency
Security Incident AccountabilityIncidents where accountability was clear100%Per incident
Security Governance EffectivenessSecurity Committee satisfaction score> 4.0/5.0Quarterly
Employee Security AwarenessAverage security awareness quiz score> 80%Quarterly
Security Responsibility ConfusionNumber of support tickets related to unclear security responsibilitiesDecreasingMonthly
Security Role TurnoverTurnover rate for security role holders< 15%Annual
Security Role Vacancy Rate(# of vacant security roles / # of total security roles) × 100< 10%Quarterly
Security Audit Findings Related to RolesAudit findings where root cause was unclear roles0Per audit
Incident Response TimeMean time to respond to security incidents< 1 hourMonthly
Compliance StatusRegulatory compliance score> 95%Quarterly
Security Culture IndexAggregated security culture survey scoreIncreasingAnnual
Management Security EngagementPercentage of managers who actively support security> 90%Annual
Security Reporting QualityQuality score of security reports to Board> 4.0/5.0Quarterly
Employee Security ConfidencePercentage of employees who feel confident in their security responsibilities> 80%Annual
Security Role ClarityPercentage of employees who understand their security responsibilities> 90%Annual
Governance Decision SpeedAverage time for Security Committee to make decisions< 2 weeksPer decision

Dashboard Sample

┌─────────────────────────────────────────────────────────────────────┐
│        SECURITY ROLES AND RESPONSIBILITIES DASHBOARD                  │
│                    [Organization] — [Month Year]                        │
├─────────────────────────────────────────────────────────────────────┤
│  ROLE DEFINITION: 100%      ██████████████████████  Target: 100%   │
│  JD SECURITY INCL: 100%      ██████████████████████  Target: 100%   │
│  CONTRACT CLAUSE: 100%       ██████████████████████  Target: 100%   │
│  COMMUNICATION: 100%         ██████████████████████  Target: 100%   │
│  ONBOARD BRIEFING: 100%      ██████████████████████  Target: 100%   │
│  ANNUAL TRAINING: 96%        ████████████████████░░  Target: 100%   │
│  COMMITTEE MEETS: 100%       ██████████████████████  Target: 100%   │
│  BOARD REPORTS: 100%         ██████████████████████  Target: 100%   │
│  DATA OWNER COV: 100%        ██████████████████████  Target: 100%   │
│  SYSTEM OWNER COV: 98%       ████████████████████░░  Target: 100%   │
│  ROLE REVIEW: 100%           ██████████████████████  Target: 100%   │
│  VACANCY RATE: 5%            ███░░░░░░░░░░░░░░░░░░░  Target: <10%  │
│  TURNOVER: 12%               ██████░░░░░░░░░░░░░░░░  Target: <15%  │
│  AWARENESS SCORE: 85%        ██████████████████░░░░  Target: >80%  │
│  CULTURE INDEX: 4.2/5.0      ██████████████████████  Target: >4.0 │
└─────────────────────────────────────────────────────────────────────┘

Common Pitfalls and How to Avoid Them

Pitfall 1: "Security Is IT's Job"

Symptom: All security responsibilities are assigned to IT, with no business ownership, no executive accountability, and no end-user responsibility.

Reality: Security is a business responsibility, not just an IT responsibility. When only IT owns security, business units bypass security for convenience, data owners don't classify data, and executives don't prioritize security.

Solution:

  • Define security roles across all business functions
  • Assign data owners and system owners in business units
  • Include business managers in security governance
  • Train business users on their security responsibilities
  • Make security a business KPI, not just an IT metric

Pitfall 2: "The CISO Reports to the CIO"

Symptom: CISO reports to the CIO, creating a conflict of interest where security is subordinate to IT objectives.

Reality: When security reports to IT, security priorities may be overridden by IT operational priorities (e.g., patch deployment delayed because IT is busy with a project). The CISO needs independence to challenge IT when security requires it.

Solution:

  • CISO should report to the CEO, COO, or a risk committee for independence
  • If reporting to CIO is unavoidable, establish a dotted-line reporting to the Board or Audit Committee for independence
  • Define explicit escalation paths for security vs. IT conflicts
  • Ensure the CISO has a seat at the executive table

Pitfall 3: "We Have a Security Role, But No One Fills It"

Symptom: Security roles are defined on paper but vacant, understaffed, or filled by people without the right skills.

Reality: A vacant CISO role or an underqualified security manager is worse than no role at all because it creates a false sense of security. "We have a CISO" sounds good, but if the CISO is also the IT manager with no security expertise, the role is ineffective.

Solution:

  • Define competency requirements for each security role
  • Budget appropriately for security staffing
  • Use virtual CISO or outsourced security for smaller organizations
  • Invest in training and certification for security role holders
  • Cross-train backup personnel for critical security roles

Pitfall 4: "Roles Are Defined, But Not Communicated"

Symptom: Beautiful security roles and RACI matrices exist in a document that no one has read.

Reality: If employees don't know their security responsibilities, the roles don't matter. Communication must be active, repeated, and reinforced, not just a one-time document dump.

Solution:

  • Integrate security responsibilities into onboarding
  • Annual refresher training on responsibilities
  • Manager-led team discussions of security responsibilities
  • Intranet knowledge base with easy access to role information
  • Visual aids (posters, cards, screensavers) reinforcing key responsibilities
  • Regular reminders through newsletters and campaigns

Pitfall 5: "Roles Are Never Updated"

Symptom: Security roles and job descriptions are written once and never updated, even after reorganization, new technology, or new regulations.

Reality: Security roles must evolve with the organization. A role defined for a 50-person company is not appropriate for a 500-person company. New technologies (cloud, AI, IoT) require new security roles. New regulations (DPDP Act) require new privacy roles.

Solution:

  • Annual review of all security roles
  • Trigger review upon organizational change (reorganization, merger, acquisition)
  • Trigger review upon new technology adoption
  • Trigger review upon new regulatory requirements
  • Assign role review accountability to Security Manager or HR

Pitfall 6: "Everyone Is Responsible for Security, So No One Is"

Symptom: Security is "everyone's responsibility" but no one is accountable for specific outcomes.

Reality: While security culture requires everyone to care about security, governance requires specific accountability. "Everyone is responsible" is a cop-out if no one is accountable for specific decisions, actions, and outcomes.

Solution:

  • Define specific accountability for each security outcome (who is the single point of accountability)
  • Use RACI to ensure there is one "A" (Accountable) for every critical activity
  • Hold individuals (not just teams) accountable for security outcomes
  • Include security accountability in performance evaluations and compensation

Pitfall 7: "We Outsource Security, So We Don't Need Internal Roles"

Symptom: Organization outsources all security functions and has no internal security ownership.

Reality: Outsourced security is a delivery model, not an accountability model. The organization remains accountable for security outcomes. Without internal security roles, there is no one to manage the outsourced provider, evaluate their performance, or make security decisions.

Solution:

  • Define internal security governance roles even when security is outsourced
  • Assign an internal security manager or liaison to oversee outsourced functions
  • Maintain internal accountability for security outcomes (CISO or equivalent)
  • Require regular reporting and governance reviews with outsourced providers
  • Define internal roles for decision-making that cannot be outsourced (risk acceptance, policy approval, incident escalation)

Pitfall 8: "Security Roles Conflict with Business Operations"

Symptom: Security roles are designed in isolation from business operations, creating friction and resistance.

Reality: Security roles must be designed to enable business, not hinder it. When security roles are seen as bureaucratic obstacles, they are ignored or bypassed.

Solution:

  • Design security roles with business input
  • Align security roles with business objectives
  • Define security roles as business enablers, not just protectors
  • Include business managers in security governance
  • Measure security role performance by both security and business outcomes

Illustrative Scenarios

Illustrative scenario, a composite example for guidance, not a specific Singahi engagement or a verified outcome.

Illustrative Scenario 1: Indian Fintech Startup, Security Role Maturity Journey

Organization: A fintech startup in Bengaluru with 120 employees, handling payment processing and customer financial data. Context: Rapidly scaling from 20 to 120 employees in 18 months. No formal security roles. Security was handled by the CTO as an additional duty. No security governance. No data owners. No security committee. RBI compliance was approaching. Series B funding required security maturity. Challenge: Need to establish security roles and governance quickly without slowing down the business. Limited budget for dedicated security staff. Engineering culture resistant to formal security structures. Approach:

  1. Week 1-2: The consultant conducted a security role gap assessment. Found: CTO handling all security informally, no CISO, no security team, no data owners, no system owners, no security governance, no role definitions, no security in job descriptions. Risk: High (RBI non-compliance, PCI DSS gaps, investor concern).
  2. Week 3-4: Designed a lean security governance model suitable for a startup:
    • CISO: Hired a fractional CISO (2 days/week) with startup experience
    • Security Lead: Promoted a senior engineer to Security Lead (full-time, with training budget)
    • Security Champion Program: Trained 5 engineers as security champions (one per team, 20% time allocation)
    • Data Owners: Assigned product managers as data owners for their product data
    • System Owners: Assigned tech leads as system owners for their services
    • Security Committee: CTO, CISO, Engineering Head, Product Head, Legal, monthly meetings
  3. Week 5-6: Implemented role documentation and communication:
    • Created role definitions for all security roles
    • Updated all job descriptions with security addenda
    • Conducted security responsibility training for all employees
    • Created RACI matrix for key security activities
    • Published security roles on the company intranet
    • Integrated security responsibilities into onboarding (new hire security briefing)
  4. Week 7-8: Activated governance:
    • First Security Committee meeting convened
    • CISO began monthly reporting to the CEO (who reported to the Board)
    • Security Champions began weekly security sync meetings
    • Data owners and system owners received targeted training on their responsibilities
    • Security role performance indicators added to quarterly performance reviews
  5. Week 9-12: Operationalized and measured:
    • Security roles began operating in practice
    • Security incidents started being reported through defined channels
    • Security decisions began flowing through the Security Committee
    • Metrics tracked: role communication completion, training completion, incident response time, audit readiness
  6. Ongoing: Continuous improvement:
    • Quarterly role review
    • Annual governance effectiveness assessment
    • Security role expansion as the company grew (added SOC analyst, compliance analyst, privacy officer) Results:
  • Security role definition coverage: 100% of roles defined within 8 weeks
  • Job description security inclusion: 100% of employees have security responsibilities in their JDs
  • Security training completion: 100% of employees within 4 weeks of rollout
  • Security Committee operational: Monthly meetings started, 100% attendance
  • CISO reporting: Monthly CEO reports, quarterly Board updates
  • RBI compliance readiness: Security governance met RBI requirements for fintechs
  • PCI DSS: Security roles satisfied PCI DSS Req 12.4
  • Series B funding: Security governance was a positive factor in due diligence
  • Security incident reporting: Increased from 2/month (informal) to 15/month (formal, more issues being caught)
  • Security culture shift: Engineers began viewing security as a shared responsibility, not a security team burden Key Lesson: Startups can establish effective security governance without heavy bureaucracy. A lean model with a fractional CISO, security champions, and clear role definitions can achieve enterprise-level accountability at startup scale.

Illustrative Scenario 2: Indian Manufacturing Enterprise, Decentralized to Centralized Governance Transformation

Organization: A large manufacturing conglomerate in India with 5,000+ employees across 8 manufacturing plants and 3 corporate offices. Diverse business units (automotive, textiles, chemicals). Context: Highly decentralized IT and security structure. Each plant had its own IT manager handling security independently. No central CISO. No unified security governance. Different plants had different security standards. Corporate security was managed by the Corporate IT Director as a secondary responsibility. Recent ransomware incident at one plant ( loss) exposed governance gaps. Challenge: Transform from decentralized, inconsistent security governance to centralized governance while respecting business unit autonomy. Large organization with unionized workforce, legacy systems, and diverse plant cultures. Approach:

  1. Phase 1: Assessment (Month 1-2): The consultant conducted a complete security governance assessment across all plants and corporate offices. Found: 8 different security approaches, no central CISO, no data owners, no system owners, no security committee, inconsistent job descriptions, no security in performance evaluations, plant IT managers had varying security competency. Risk: Critical (ransomware exposure, regulatory risk, operational risk).
  2. Phase 2: Governance Design (Month 3-4): Designed a hybrid governance model (hub-and-spoke) to balance central governance with local autonomy:
    • Central CISO: Full-time CISO at corporate headquarters, reporting to CEO
    • Central Security Team: Corporate SOC, GRC, Security Architecture, and Incident Response teams
    • Plant Security Coordinators: Each plant designated a Security Coordinator (existing IT manager or new hire) who reported to Plant Head with dotted-line to CISO
    • Business Unit Security Leads: Each business unit (automotive, textiles, chemicals) had a Security Lead reporting to BU Head with dotted-line to CISO
    • Security Committee: CISO, CIO, Plant Heads, BU Heads, Legal, HR, quarterly meetings
    • Plant Security Committees: Local versions at each plant for local issues
  3. Phase 3: Role Definition (Month 5-6): Created detailed role definitions for 25+ security roles across the organization. Updated all job descriptions (5,000+ employees) with security addenda. Created RACI matrix for 50+ security activities. Defined security competency requirements for each role. Created security role training curriculum.
  4. Phase 4: Communication and Integration (Month 7-8): Massive communication campaign:
    • Town halls at each plant and corporate office
    • Manager briefing sessions (500+ managers trained)
    • Security responsibility cards distributed to all employees
    • Intranet knowledge base launched
    • HR integration: security responsibilities added to all performance evaluation templates
    • Union consultation: worked with union leaders to communicate security responsibilities as part of job safety
  5. Phase 5: Governance Activation (Month 9-10): Activated the new governance structure:
    • First central Security Committee meeting
    • Plant Security Committees began monthly meetings
    • CISO began quarterly Board reporting
    • Security Coordinators began weekly sync calls with central team
    • Security incident reporting consolidated into central SOC
    • Security metrics dashboard deployed across all locations
  6. Phase 6: Operationalization (Month 11-12): Full operation under new governance:
    • Central security policies deployed across all plants
    • Unified security standards implemented
    • Central SOC monitoring all plants
    • Incident response coordinated centrally
    • Security audits conducted centrally with plant participation
    • Continuous improvement process established
  7. Ongoing: Maturity advancement:
    • Year 2: Achieved Level 4 (Quantitatively Managed), all metrics tracked, governance effectiveness measured, role performance evaluated
    • Year 3: Targeting Level 5 (Optimizing), with continuous improvement of roles and culture Results:
  • Security role definition: 100% of 5,000+ employees have defined security responsibilities
  • CISO appointed: Full-time CISO reporting to CEO (achieved independence from IT)
  • Security Committee: Quarterly meetings with 100% executive attendance
  • Plant Security Coordinators: 8 coordinators trained and operational
  • Security metrics: 15 KPIs tracked across all locations
  • Incident response: Mean time to respond reduced from 48 hours to 4 hours
  • Security incidents: Increased reporting (from 5/month to 45/month), more issues being caught, not more issues occurring
  • Ransomware readiness: Achieved 95% patch compliance, 100% backup coverage, incident response drills at all plants
  • Regulatory compliance: Met ISO 27001 requirements, industry-specific regulations
  • Employee satisfaction: Security culture survey improved from 2.8/5.0 to 4.1/5.0
  • Business case: preventing one similar ransomware incident would pay for several years of the governance programme Key Lesson: Large decentralized organizations can transition to effective security governance without destroying local autonomy. The hybrid model (central governance + local coordination) respects business unit culture while unifying security accountability.

Multi-Framework Mapping

NIST SP 800-53 Rev 5 Mapping

NIST ControlDescriptionA.5.2 Mapping
PM-1Information Security Program PlanSecurity program and role definition
PM-2Information Security Program LeadershipCISO and senior security leadership
PM-3Information Security and Privacy ResourcesResource allocation for security roles
AT-3Role-Based TrainingRole-specific security training
PS-6Access AgreementsSecurity responsibilities in access agreements
PS-9Position DescriptionsSecurity roles and responsibilities in position descriptions
PM-29Risk Management Program Leadership RolesSenior accountable official for risk management
PL-1Policy and Procedures (Planning)Planning policy defines roles
PL-2System Security PlanSystem security plans define roles
RA-1Policy and Procedures (Risk Assessment)Risk assessment roles defined
CA-1Policy and Procedures (Assessment, Authorization and Monitoring)Audit and assessment roles defined
IR-1Incident Response PolicyIncident response roles defined
CM-1Configuration Management PolicyConfiguration management roles defined
SA-1System and Services Acquisition PolicyAcquisition security roles defined
SI-1System and Information Integrity PolicyIntegrity monitoring roles defined

COBIT 2019 Mapping

COBIT PracticeDescriptionA.5.2 Mapping
EDM01Ensure Governance FrameworkGovernance structure and role definition
APO01Managed I&T Management FrameworkDefines roles and responsibilities (APO01.02)
APO07Managed PeopleHR processes include security responsibilities
BAI01Managed ProgramsProgram management includes security roles
BAI02Managed RequirementsRequirements management includes security roles
DSS01Managed OperationsOperations roles include security
DSS05Managed Security ServicesSecurity service roles defined
DSS06Managed Business Process ControlsBusiness process security roles
MEA01Managed PerformancePerformance monitoring roles
MEA02Managed System of Internal ControlInternal control roles defined

PCI DSS v4.0.1 Mapping

PCI DSS RequirementA.5.2 Mapping
Req 12.1.3Security roles and responsibilities defined and acknowledged
Req 12.1.4Executive responsibility for information security assigned
Req 12.6Security awareness, including role-specific training
Req 12.10.1Incident response roles defined in the IR plan
Req 11.4Penetration testing performed by qualified, independent testers
Req 6.2Secure development of bespoke and custom software

DPDP Act 2023: Relevant Provisions

DPDP Act SectionA.5.2 Mapping
Section 8(5)Reasonable security safeguards require accountable roles
Section 8(4)Appropriate technical and organisational measures requires role definition
Section 6(1)Consent covers only the data needed for the stated purpose; requires data owner role
Sections 5–6Notice and consent define the purposes; requires accountability
Section 8(6)Personal data breach intimation requires incident response roles
Section 8(7)Storage limitation (erase once the purpose is served) requires data owner accountability

CIS Controls v8 Mapping

CIS ControlA.5.2 Mapping
Control 1Inventory and Control of Enterprise Assets, requires asset owner roles
Control 2Inventory and Control of Software Assets, requires software asset owner roles
Control 14Security Awareness and Skills Training, requires training roles and accountability
Control 6Access Control Management, requires access control roles
Control 17Incident Response Management, requires incident response roles (17.1 designates personnel)
Control 18Penetration Testing, requires testing roles and accountability

ITIL 4 Mapping

ITIL PracticeA.5.2 Mapping
Organizational Change ManagementSecurity roles in change management
Workforce and Talent ManagementSecurity role definition and competency
Relationship ManagementSecurity stakeholder roles
Service DeskSecurity incident triage roles
Incident ManagementSecurity incident response roles
Problem ManagementSecurity problem investigation roles
Change EnablementSecurity change approval roles
Risk ManagementSecurity risk assessment roles
Information Security ManagementSecurity governance roles
Knowledge ManagementSecurity knowledge owner roles

Regulatory and Industry Context

India

RegulationSecurity Role RequirementsKey Mandates
DPDP Act 2023Data Protection Officer (DPO) for significant data fiduciariesSection 8(1) (Data Fiduciary responsibility) requires accountability; Section 10(2)(a) mandates a DPO for Significant Data Fiduciaries; Section 8(4) (Appropriate technical and organisational measures) requires role definition
IT Act 2000 and SPDI Rules 2011Grievance Officer (SPDI Rules r.5(9)); defined roles support s.43A reasonable security practicesCompensation claims under s.43A
RBI Cybersecurity FrameworkCISO or equivalent for banks, NBFCs, payment systemsCybersecurity framework mandates CISO, security committee, and defined security roles
SEBI CSCRF (2024)CISO, CTO security roles for brokers, exchanges, depositoriesCyber resilience framework mandates security governance roles
IRDAI GuidelinesInformation Security Officer for insurersInformation security guidelines mandate security officer and governance
CERT-In GuidelinesSecurity contact point for incident reportingSecurity contact role for reporting incidents to CERT-In
Companies Act 2013Board responsibility for risk managementBoard oversight includes cyber risk; requires governance structure
Digital IndiaSecurity officer for government e-servicesGovernment e-services require security accountability

International

RegulationSecurity Role RequirementsKey Mandates
PCI DSS v4.0.1Security responsibilities assigned and documentedReq 12.4: Security roles must be assigned to individuals; Req 12.6: Security awareness must be role-based
GDPRData Protection Officer (DPO) for certain organizationsArt 37: DPO must be designated for certain controllers/processors; Art 39: DPO tasks must be defined
HIPAASecurity Official and Privacy OfficialSecurity Rule: Covered entities must designate Security Official and Privacy Official
SOXIT governance and security rolesIT general controls require defined roles and responsibilities
NIST CSF 2.0Governance roles for cybersecurityGV.OC: Governance requires organizational culture and role definition
CCPA/CPRAPrivacy roles for California consumersRequires accountability for consumer privacy
LGPDDPO for Brazilian organizationsSimilar to GDPR DPO requirements
PDPAData protection roles for SingaporeRequires designated data protection officer
POPIAInformation Officer for South AfricaRequires designated information officer

Roles and Responsibilities (RACI) for A.5.2 Implementation

RACI Matrix for A.5.2 Implementation

ActivityCISOSecurity ManagerHR HeadIT ManagerBusiness Unit HeadsLegalCompliance OfficerBoard/CEO
Define security governance structureR/ACCCCCCA
Define security rolesARCCCCCC
Update job descriptionsCCR/ACCCCI
Update employment contractsCCR/ACCRCI
Communicate security responsibilitiesARCCCCII
Establish Security CommitteeRCCCCCCA
Conduct security trainingARCCCCCI
Assign data ownersARCCRCCI
Assign system ownersARCRCCCI
Define third-party security rolesARCCCRCI
Review and update rolesARCCCCCI
Track security role metricsARCCCCCI
Report security roles to BoardRCCCCCCA
Enforce security responsibilitiesACRCCCCI
Audit security rolesARCCCCRI
Manage security role budgetRCCCCCCA

Role Descriptions for A.5.2 Implementation

RoleKey Responsibilities for A.5.2Required Skills
CISOOwn the security governance model; define security roles; approve role definitions; establish Security Committee; report to Board; ensure role effectiveness; approve role changesSecurity leadership, governance design, organizational development, communication
Security ManagerMaintain role documentation; coordinate role assignment; track role performance; manage role review cycle; support Security Committee; communicate roles to staffDocumentation, coordination, project management, communication, training
HR HeadUpdate job descriptions with security responsibilities; update employment contracts; integrate security into performance evaluations; support onboarding security briefing; manage role competency frameworkHR management, employment law, organizational development, training management
IT ManagerDefine technical security roles; assign system owners; communicate technical security responsibilities; ensure IT staff understand their security rolesIT management, technical security, communication, leadership
Business Unit HeadsAssign data owners within their unit; communicate business security responsibilities; enforce security accountability within their teams; participate in Security CommitteeBusiness management, leadership, security awareness, communication
LegalReview role definitions for legal compliance; review contracts for security role clauses; advise on regulatory role requirements; support governance charterLegal expertise, regulatory knowledge, contract review
Compliance OfficerEnsure regulatory role requirements are met; track compliance with role mandates; support audit of security roles; report compliance statusCompliance expertise, regulatory knowledge, audit
Board/CEOApprove security governance structure; receive security role reports; hold management accountable for security roles; allocate resources for security rolesGovernance, leadership, strategic decision-making, accountability

Documentation and Evidence Requirements

ISO 27001 does not mandate specific documents for this control. If you select it, keep the documented information you need to show it is planned and working (clause 7.5), and set retention in your own retention schedule. Typical records:

DocumentPurposeSuggested retentionOwner
Information Security Roles and Responsibilities PolicyGovernance frameworkPer retention scheduleCISO
Security Governance CharterGovernance structure definitionPer retention scheduleCISO
Security Committee CharterCommittee governancePer retention scheduleCISO
Security Roles and Responsibilities MatrixRole-to-responsibility mappingPer retention scheduleSecurity Manager
RACI MatrixActivity accountabilityPer retention scheduleSecurity Manager
Job Description Security AddendaSecurity responsibilities in rolesPer retention scheduleHR
Updated Employment ContractsSecurity clauses in contractsDuration of employment + 7 yearsHR
Security Role Assignment RecordsWho is assigned to what rolePer retention scheduleSecurity Manager
Security Committee Meeting MinutesGovernance activity evidencePer retention scheduleSecurity Manager
Board Security ReportsBoard-level security reportingPer retention scheduleCISO
Security Communication RecordsEvidence of responsibility communicationPer retention scheduleSecurity Manager
Onboarding Security Briefing RecordsNew hire security communicationPer retention scheduleHR
Annual Security Training RecordsTraining completion evidencePer retention scheduleHR / Security
Security Role Review RecordsRole review and update evidencePer retention scheduleSecurity Manager
Competency Assessment RecordsRole holder competency evidencePer retention scheduleHR
Performance Evaluation RecordsSecurity responsibility enforcementPer retention scheduleHR
Data Owner RegisterData ownership assignmentPer retention scheduleSecurity Manager
System Owner RegisterSystem ownership assignmentPer retention scheduleSecurity Manager
Third-Party Security Role DocumentationVendor security role definitionPer retention scheduleSecurity Manager
Security Role Metrics ReportsRole performance evidencePer retention scheduleSecurity Manager
Security Role Gap AnalysisAssessment of role gapsPer retention scheduleSecurity Manager
Security Role Project PlanImplementation evidencePer retention scheduleSecurity Manager
Security Role Training MaterialsTraining contentPer retention scheduleSecurity Manager
Security Role Intranet / Knowledge BaseAccessible role documentationCurrent version + 7 yearsSecurity Manager
Employee Acknowledgment RecordsEvidence of responsibility acknowledgmentPer retention scheduleHR
Security Role Audit RecordsAudit of role implementationPer retention scheduleSecurity Manager
Security Role Change RecordsEvidence of role changesPer retention scheduleSecurity Manager
Security Role Communication PlanCommunication strategyPer retention scheduleSecurity Manager
Security Role Competency FrameworkSkills requirementsPer retention scheduleSecurity Manager
Security Role Budget and Resource RecordsResource allocationPer retention scheduleCISO

Evidence for Audit

Audit QuestionEvidence Required
"Are security roles formally defined?"Roles and Responsibilities Matrix, Role Definitions, Policy
"Who is the CISO or security leader?"Appointment letter, Org chart, Governance charter
"Are security responsibilities in job descriptions?"Job descriptions, HR records
"How do you communicate security responsibilities?"Training records, onboarding records, communication records, intranet
"Is there a security governance structure?"Governance charter, Security Committee charter, meeting minutes
"Does security report to the Board?"Board reports, meeting minutes, governance charter
"Are there data owners and system owners?"Data Owner Register, System Owner Register
"How do you handle third-party security roles?"Vendor contracts, SLA security clauses, third-party role documentation
"Are security roles reviewed and updated?"Role review records, annual review documentation
"Are security responsibilities enforced?"Performance evaluation records, disciplinary records, enforcement evidence

Continuous Improvement

Improvement Cycle

Plan → Implement → Measure → Review → Improve

Plan: Set targets for role definition, communication, governance, competency, and enforcement.

Implement: Deploy role definitions, governance structure, communication, HR integration, and training.

Measure: Track KPIs, conduct surveys, analyze audit results, monitor role effectiveness, and assess governance.

Review: Monthly metrics review, quarterly governance review, annual complete review, post-incident review, and lessons learned sessions.

Improve: Update role definitions, refine governance, enhance communication, improve training, and adopt new tools.

Improvement Triggers

TriggerAction
Organizational change (reorganization, merger, acquisition)Review all security roles and update governance structure
New technology adoption (cloud, AI, IoT)Define new security roles for new technology; update existing roles
New regulation (DPDP Act, new RBI guidelines)Update role definitions to reflect regulatory requirements; add compliance roles
Security incidentReview roles and responsibilities related to incident; identify gaps
Audit findingUpdate role definitions or governance to address finding
Role holder turnoverReview role; ensure knowledge transfer; update documentation
Business expansionAdd new security roles for new business units, locations, or products
Security maturity advancementRefine roles as organization moves from Level 1 to Level 5
Industry benchmarkCompare role maturity with industry; set improvement targets
Employee feedbackRefine role definitions, communication, or training based on feedback
Board feedbackEnhance governance reporting, Board engagement, or strategic alignment
Third-party changeUpdate third-party security roles when vendors change or new vendors are added
Budget changeAdjust role scope, staffing, or outsourcing based on budget changes
Skills gap identifiedAdd training, certification, or recruitment to address skills gaps

Maturity Advancement Path

From LevelTo LevelKey ActionsTypical Timeline
1 (Ad-hoc)2 (Managed)Appoint CISO/vCISO; define basic roles; informal governance1–2 months
2 (Managed)3 (Defined)Formal role definitions; governance charter; Security Committee; HR integration; communication3–4 months
3 (Defined)4 (Quantitatively Managed)Metrics tracking; performance evaluation integration; competency framework; regular review3–4 months
4 (Quantitatively Managed)5 (Optimizing)Continuous improvement of roles; culture measurement; lessons from incidents built in1–2 years

FAQ

Q1: Does ISO 27001 require a CISO?

A: No. ISO 27001 does not mandate a specific job title or reporting structure. However, the standard requires a designated person or group to be responsible for information security. For small organizations, this could be an IT manager or founder with security responsibilities. For larger organizations, a dedicated CISO is strongly recommended. The key is clear accountability, not a specific title.

Q2: Can a single person hold multiple security roles?

A: Yes, in smaller organizations. However, be careful about conflicting roles (e.g., a system administrator who is also the security auditor of their own systems). Use segregation of duties (A.5.3) principles to ensure checks and balances. A single person can be both Security Manager and SOC Analyst, but should not be both System Administrator and Security Auditor for the same systems.

Q3: How do we define security roles for a very small organization (under 10 employees)?

A: Keep it simple. Assign a "Security Owner" (could be the CEO/founder). Define 3-5 key security responsibilities for each role (CEO, developer, sales, operations). Use a one-page security roles document. Consider a virtual CISO or security consultant for governance. The key is documentation and communication, not complexity.

Q4: Should the CISO report to the CIO or the CEO?

A: Ideally, the CISO reports to the CEO for independence. Reporting to the CIO creates a conflict of interest because the CIO is responsible for IT operations, and the CISO may need to challenge IT decisions for security reasons. If the CISO must report to the CIO, establish a dotted-line reporting to the Board or Audit Committee to maintain independence. For small organizations, the CISO reporting to the CEO is often the only practical option anyway.

Q5: How do we assign data owners when no one wants to be accountable?

A: Make data ownership part of the role, not an optional add-on. Assign data ownership to the business unit head or product manager who benefits from the data. Include data ownership in their job description and performance evaluation. Make it clear that data ownership is a business responsibility, not a security burden. If necessary, escalate to executive leadership to assign accountability.

Q6: What if we don't have budget for a full security team?

A: Start with a virtual CISO (part-time consultant) and build incrementally. Use the "security champion" model where one person per team dedicates 10-20% of their time to security. Outsource security operations (SOC, monitoring) to a Managed Security Service Provider (MSSP). Use automation to reduce manual security work. The key is to define roles and accountability, even if the delivery is outsourced or shared.

Q7: How do we enforce security responsibilities if there's no disciplinary process?

A: Start by including security responsibilities in job descriptions and performance evaluations. Use positive reinforcement (recognition, bonuses) for good security behavior. For violations, use coaching and retraining before disciplinary action. Work with HR to establish a fair disciplinary process. Reference A.6.4 (Disciplinary process) for guidance. The goal is accountability, not punishment.

Q8: How do we handle security roles in a merger or acquisition?

A: Conduct a security role mapping exercise early in the integration. Identify overlapping roles, gaps, and conflicts. Harmonize job descriptions and security responsibilities. Decide on a unified governance model (centralized, decentralized, or hybrid). Communicate role changes clearly and early. Retain key security personnel from both organizations. Plan for cultural integration of security roles.

Q9: Should security roles be the same across all business units?

A: Core security roles (CISO, Security Manager, Compliance) should be consistent across the organization. However, business unit-specific roles (data owners, system owners, business liaisons) will naturally differ based on each unit's functions and data. The governance model should be consistent, but the implementation of roles should be tailored to business needs.

Q10: How do we measure if our security roles are effective?

A: Track KPIs: incident response time, audit findings, compliance status, employee awareness scores, role vacancy rate, training completion, and security culture index. Conduct surveys asking employees if they understand their security responsibilities. Review whether security incidents are properly escalated and managed. The ultimate measure is whether security outcomes are improving.

Q11: What is the difference between a Data Owner and a System Owner?

A: A Data Owner is accountable for a specific data asset (e.g., customer data, financial data), its classification, access, quality, and protection. A System Owner is accountable for a specific information system (e.g., CRM, ERP, email server), its security, availability, compliance, and maintenance. A Data Owner may be a business manager (e.g., Head of Sales owns customer data), while a System Owner may be an IT manager (e.g., IT Manager owns the CRM system). They must coordinate on access controls and security.

Q12: How do we communicate security responsibilities to a remote or hybrid workforce?

A: Use the same communication channels but adapted for remote: digital onboarding, virtual training, intranet/knowledge base, video briefings, email campaigns, and virtual town halls. Use collaboration tools (Slack, Teams) for security reminders. Ensure remote employees have the same access to security role documentation as office employees. Conduct virtual phishing simulations and security quizzes. Use screen savers and desktop wallpapers with security reminders.

Q13: What should be in a Security Governance Charter?

A: The charter should define: governance purpose and scope, security roles and reporting structure, Security Committee composition and responsibilities, decision authority and escalation paths, meeting cadence and reporting requirements, and review cycle. See the Security Committee Charter section above for a template.

Q14: How do we handle security roles for contractors and temporary staff?

A: Define security responsibilities for contractors in their contracts and terms of engagement. Assign a security liaison or manager to oversee contractor security. Provide contractor-specific security training. Limit contractor access to only what they need. Require contractors to report security incidents. Include security responsibilities in contractor performance reviews. Ensure contractors return all assets and access is revoked upon contract completion (reference A.6.5 and A.6.6).

Q15: Can we use AI or automation to manage security roles?

A: Yes, AI and automation can help: automated onboarding security briefing delivery, AI-assisted role definition based on job function, automated role review reminders, AI-driven competency gap analysis, automated security metrics collection, and AI-powered security culture monitoring. However, human judgment is still needed for governance decisions, role assignments, and accountability. Use AI to augment, not replace, human governance.


References and Further Reading

Standards and Guidelines

  1. ISO/IEC 27001:2022: Information Security, Cybersecurity and Privacy Protection, Information Security Management Systems, Requirements. ISO, 2022.
  2. ISO/IEC 27002:2022: Information Security, Cybersecurity and Privacy Protection, Information Security Controls. ISO, 2022.
  3. NIST SP 800-53 Rev 5: Security and Privacy Controls for Information Systems and Organizations. NIST, 2020.
  4. NIST CSF 2.0: Cybersecurity Framework. NIST, 2024.
  5. COBIT 2019: Control Objectives for Information and Related Technologies. ISACA, 2019.
  6. ITIL 4: IT Service Management. AXELOS, 2019.
  7. CIS Controls v8: Center for Internet Security, 2021.
  8. PCI DSS v4.0: Payment Card Industry Data Security Standard. PCI SSC, 2022.
  9. OWASP SAMM v2.0: Software Assurance Maturity Model. OWASP, 2020.
  10. BSIMM: Building Security In Maturity Model (current edition BSIMM15, Black Duck).

Security Governance and Leadership

  1. "CISO Compass: Navigating Cybersecurity Leadership Challenges with Insights from Pioneers": Todd Fitzgerald, CRC Press, 2019.
  2. "The CISO Evolution: Business Knowledge for Cybersecurity Executives": Matthew K. Sharp and Kyriakos Lambros, Wiley, 2022.
  3. "Tribe of Hackers: Leadership": Marcus J. Carey and Jennifer Jin, Wiley, 2021.
  4. "Cybersecurity Leadership: Powering the Modern Organization": Mansur Hasib, Leadership + Design, 2019.
  5. "The Security Culture Playbook": Perry Carpenter and Kai Roer, Wiley, 2022.
  6. "Building an Effective Security Organization": Various authors, SANS Institute.

Organizational Development and HR

  1. "Human Resource Management": Gary Dessler, Pearson, 2022.
  2. "The HR Scorecard": Brian Becker, Mark Huselid, and Dave Ulrich, Harvard Business Press, 2001.

Indian Regulatory Resources

  1. Digital Personal Data Protection Act 2023: Government of India, 2023.
  2. RBI Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices: Reserve Bank of India, 7 November 2023 (in force from 1 April 2024); and RBI Cyber Security Framework in Banks: circular of 2 June 2016.
  3. SEBI Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities, circular of 20 August 2024.
  4. IRDAI Guidelines on Information and Cybersecurity: Insurance Regulatory and Development Authority of India, 2023.
  5. IT Act 2000 (as amended): Ministry of Electronics and Information Technology, India.
  6. CERT-In Security Guidelines: https://www.cert-in.org.in/
  7. MeitY Cybersecurity Guidelines: Ministry of Electronics and Information Technology, India.
  8. Companies Act 2013: Ministry of Corporate Affairs, India.

Industry Research

  1. IBM Cost of a Data Breach Report 2024: IBM Security and Ponemon Institute, 2024.
  2. Verizon Data Breach Investigations Report 2024: Verizon, 2024.
  3. SANS Security Culture Report: SANS Institute, 2023.

How Singahi can help

Singahi is one team for compliance, assessment and managed security. We help growing companies implement and certify ISO 27001:2022, and stay secure afterward.


Continue the toolkit

How we can help

Working toward this?

If a certification or a customer's security questionnaire is what brought you here, tell us where you are. We'll give you an honest read on the work and the timeline, with no obligation.

What happens next

  1. Tell us the trigger

    A questionnaire, an audit date or an investor ask. The short form or a call both work.

  2. A practitioner replies

    A senior practitioner, not a bot, within four business hours.

  3. You get a scoped next step

    An honest view of what the work involves. No pressure, no theatre.