Roles and Responsibilities

Annex A5.2 – Information Security Roles and Responsibilities 

The Annex 5.2 Information Security Roles and Responsibilities control is extremely important as it not only sets out the roles and responsibilities of those involved in information security, but sets out clear expectations.

 

Some will have you believe that this is complicated but it’s not!

 

Let’s take this requirement apart and show you how it works.

What does the standard actually expect?

Control 5.2 states;

The standard states that “Information security roles and responsibilities shall be defined and allocated according to the organisations needs” (A5.2 Roles and Responsibilities)

 

Note: ‘roles’ and ‘responsibilities’ and ‘defined’ and ‘allocated’;  this means there are four requirements that we need to consider..

According to the standard the purpose of this control is to “establish a defined, approved and understood structure for the implementation, operation and management of information security within your organisation.”

ISO 27001 5.2 Responsibilities Man

What do you need to do?

You’re going to refer to your ‘Interested Parties’ that you identified previously when you looked at internal and external parties.  In the main, we’ll focus on the internal interested parties but there may be roles and responsibilities of others that need to be considered.

Let’s imagine your interested parties looked like this;

  • Top Management
  • Employees
  • Shareholders
  • Suppliers

This is a great start, and although it won’t be all suppliers, it gives us something to consider.

Now, start a new document in Excel and call it “Roles and Responsibilities”.

In addition to the groups listed above, you should add;

  • The Management Review team
  • The Incident Response team

In the document you have created, you can have columns which clearly define what their role and responsibilities are. For example

Who

 Role

Responsibility / Authority

Top management

To provide leadership and support for the security programme.

  • Set overall business strategy
  • Allocating Resources
  • Setting and agreeing Budgets
  • Sign-off policies
  • Ensure compliance with legislation
  • Reporting breaches

 

Supplier – IT Support

Support of the Technical infrastructure

  • Back-up management
  • Cloud environment security
  • E-mail security
  • Patch Management

 

ISO 27001 Roles and Responsibilities Group

This is also a great way to demonstrate that you have assigned authorities, under Clause 5.3 Organisational Roles, Responsibilities and Authorities.  Remember that identifying their authority is about understanding what authority they have. For example, do they have authority to agree increase in budgets? Or is that someone else’s responsibility?

It’s important to allocate these roles and responsibilities in line with your information security policies, so refer to A5.1 Information Security Policies if you haven’t already defined these.

Job descriptions – Roles and Responsibilities

It’s worth remembering that there is probably already a great wealth of information available to you already, stored in your Job Descriptions (JDs).

JDs will outline the role of key people, and will explain what they are responsible for. Seek these out for key people in your organisation, and also ask for a more generic JD.  What does it say about Security and/or Data Protection? If you can, ask your HR function to include a couple of lines within the JD template, so that it makes it everyone’s responsibility to maintain security!

Once you’ve reviewed the JD’s, make sure you’re clear about the following roles and define them in the spreadsheet you have created.  These roles are;

Don’t worry if these roles don’t exist. But if they do, these people will be responsible for setting strategic direction for your information security programme, or may be actively involved in the risk management function.

Your job here is to identify the people who will take an active part in your security programme. Then you will outline what you expect of these people, and then communicate this to them. This is how you achieve buy-in to your programme, you become ISO27001 AND become a more secure business!

It’s a triple win!

What the auditor is looking for

For compliance with this control you’ll need to have in place the following;

  • Defined Roles and Responsibilities (as described above)
  • Job Descriptions (as described above)

The auditor will want to see that there is segregation of duties but this is something we’ll cover in Annex A 5.3 (Segregation of Duties), but for this control specifically the auditor will want to see that roles are defined.

ISO 27001 Controls 5.2 ticking the box

FAQ

What’s the biggest mistake you see people make with this control?

First, they don’t create a specific ‘Roles and Responsibilities’ document which identifies the key groups and individuals that will help you in your quest to achieve ISO27001. So remember to create a document.

Second, they over complicate things. Don’t feel you have to identify every role. Keep in mind the following roles and consider their impact on ISO27001;

  • CEO / Business owner
  • Information Security Manager
  • Data Protection Officer
  • Business Continuity Manager

What happens if more than one person performs a role?

That’s fine because we’re talking about a role, not a person. For example, one person can be the Information security manager and the Data Protection Officer, but their responsibilities will be very different and their authority is likely to be different too.

To satisfy this requirement, focus on the role, not the person.

What groups should I include?

This depends on the size of your business, but at a minimum you should identify the roles and responsibilities (in relation to information security) the following groups;

  • The Board
  • Management Review Team
  • Incident Management Team

There may be other groups you have in your organisation, so take a look around and define them as appropriate.

Woman looking pensive about controls around roles and responsibilities

Conclusion

Without clearly defining the roles and responsibilities of those involved in your business, and specifically in Information Security can lead to assumptions and gaps.

This is why Job descriptions are so important; They provide structure and areas of responsibility and authority.  Remembering that we often say that Information Security is EVERYONE’s responsibility, then it makes perfect sense that we communicate to people that this is the case.

If this is something you’re finding difficult, or you need help with any of the ISO 27001 Annex A controls, then get in touch and we can talk through why they’re missing the mark and not delivering what you need. For a free online quote simply provide your details and we be in touch to help with your responsibilities and roles.