Roles and Responsibilities
Annex A5.2 – Information Security Roles and Responsibilities
The Annex 5.2 Information Security Roles and Responsibilities control is extremely important as it not only sets out the roles and responsibilities of those involved in information security, but sets out clear expectations.
Some will have you believe that this is complicated but it’s not!
Let’s take this requirement apart and show you how it works.
What does the standard actually expect?
Control 5.2 states;
The standard states that “Information security roles and responsibilities shall be defined and allocated according to the organisations needs” (A5.2 Roles and Responsibilities)
Note: ‘roles’ and ‘responsibilities’ and ‘defined’ and ‘allocated’; this means there are four requirements that we need to consider..
According to the standard the purpose of this control is to “establish a defined, approved and understood structure for the implementation, operation and management of information security within your organisation.”
What do you need to do?
You’re going to refer to your ‘Interested Parties’ that you identified previously when you looked at internal and external parties. In the main, we’ll focus on the internal interested parties but there may be roles and responsibilities of others that need to be considered.
Let’s imagine your interested parties looked like this;
- Top Management
- Employees
- Shareholders
- Suppliers
This is a great start, and although it won’t be all suppliers, it gives us something to consider.
Now, start a new document in Excel and call it “Roles and Responsibilities”.
In addition to the groups listed above, you should add;
- The Management Review team
- The Incident Response team
In the document you have created, you can have columns which clearly define what their role and responsibilities are. For example
|
Who |
Role |
Responsibility / Authority |
|
Top management |
To provide leadership and support for the security programme. |
|
|
Supplier – IT Support |
Support of the Technical infrastructure |
|
This is also a great way to demonstrate that you have assigned authorities, under Clause 5.3 Organisational Roles, Responsibilities and Authorities. Remember that identifying their authority is about understanding what authority they have. For example, do they have authority to agree increase in budgets? Or is that someone else’s responsibility?
It’s important to allocate these roles and responsibilities in line with your information security policies, so refer to A5.1 Information Security Policies if you haven’t already defined these.
Job descriptions – Roles and Responsibilities
It’s worth remembering that there is probably already a great wealth of information available to you already, stored in your Job Descriptions (JDs).
JDs will outline the role of key people, and will explain what they are responsible for. Seek these out for key people in your organisation, and also ask for a more generic JD. What does it say about Security and/or Data Protection? If you can, ask your HR function to include a couple of lines within the JD template, so that it makes it everyone’s responsibility to maintain security!
Once you’ve reviewed the JD’s, make sure you’re clear about the following roles and define them in the spreadsheet you have created. These roles are;
- Chief Information Security Officer (CISO)
- Chief Technology Officer (CTO)
- Data Protection Officer (DPO)
- Information Security Manager
Don’t worry if these roles don’t exist. But if they do, these people will be responsible for setting strategic direction for your information security programme, or may be actively involved in the risk management function.
Your job here is to identify the people who will take an active part in your security programme. Then you will outline what you expect of these people, and then communicate this to them. This is how you achieve buy-in to your programme, you become ISO27001 AND become a more secure business!
It’s a triple win!
What the auditor is looking for
For compliance with this control you’ll need to have in place the following;
- Defined Roles and Responsibilities (as described above)
- Job Descriptions (as described above)
The auditor will want to see that there is segregation of duties but this is something we’ll cover in Annex A 5.3 (Segregation of Duties), but for this control specifically the auditor will want to see that roles are defined.
FAQ
What’s the biggest mistake you see people make with this control?
First, they don’t create a specific ‘Roles and Responsibilities’ document which identifies the key groups and individuals that will help you in your quest to achieve ISO27001. So remember to create a document.
Second, they over complicate things. Don’t feel you have to identify every role. Keep in mind the following roles and consider their impact on ISO27001;
- CEO / Business owner
- Information Security Manager
- Data Protection Officer
- Business Continuity Manager
What happens if more than one person performs a role?
That’s fine because we’re talking about a role, not a person. For example, one person can be the Information security manager and the Data Protection Officer, but their responsibilities will be very different and their authority is likely to be different too.
To satisfy this requirement, focus on the role, not the person.
What groups should I include?
This depends on the size of your business, but at a minimum you should identify the roles and responsibilities (in relation to information security) the following groups;
- The Board
- Management Review Team
- Incident Management Team
There may be other groups you have in your organisation, so take a look around and define them as appropriate.
Conclusion
Without clearly defining the roles and responsibilities of those involved in your business, and specifically in Information Security can lead to assumptions and gaps.
This is why Job descriptions are so important; They provide structure and areas of responsibility and authority. Remembering that we often say that Information Security is EVERYONE’s responsibility, then it makes perfect sense that we communicate to people that this is the case.
If this is something you’re finding difficult, or you need help with any of the ISO 27001 Annex A controls, then get in touch and we can talk through why they’re missing the mark and not delivering what you need. For a free online quote simply provide your details and we be in touch to help with your responsibilities and roles.
