Roles and Responsibilities
What is Roles and Responsibilities?
Clear definitions of what each position or team is expected to do, their authority levels, and their accountability relationships within an organization.
Terms that appear alongside roles and responsibilities
Each of these is named in at least one of the same controls as roles and responsibilities. The number is how many controls name both.
- information security 31 shared controls
- governance 29 shared controls
- policy 13 shared controls
- nist 9 shared controls
- security governance 8 shared controls
- security officer 8 shared controls
- compliance 7 shared controls
- incident response 7 shared controls
Frameworks that govern roles and responsibilities
What the standards actually require on roles and responsibilities
Requirements naming roles and responsibilities across 6 standards, quoted from the control text.
Roles and responsibilities for performing activities in Requirement 9 are documented, assigned, and understood
9.1.2 · Roles and responsibilities for performing activities in Requirement 9 are documented, assigned, and understood →Authorization Process. Manage the security and privacy state of organizational systems and the environments in which those systems operate through authorization processes;
NIST800-PM-10 · Authorization Process. Manage the security and privacy state of organizational systems and the environments in which those systems operate through authorization processes; Designate individuals to fulfill specific roles and responsibilities within the organizational risk →Document and communicate what each employee is responsible for in relation to information assets and their security.
CCM-HRS-09 · Personnel Roles and Responsibilities →Requires information security roles and responsibilities to be defined and allocated in line with what the organisation actually needs, so ownership of each security duty is explicit rather than assumed.
iso-27002-2022::5.2 · Information security roles and responsibilities →Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight of AI systems.
AIRMF-GV-3.2 · Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight of AI systems →Assign key roles and responsibilities for incident response, including staff from legal, IT, information security, facilities, public relations, human resources, incident responders, and analysts, as applicable.
CIS-17.5 · Assign Key Roles and Responsibilities →Questions people ask about roles and responsibilities
What is Roles and Responsibilities?
Why is Roles and Responsibilities important for compliance?
Which compliance frameworks address Roles and Responsibilities?
Where can I learn more about Roles and Responsibilities?
See how Roles and Responsibilities applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.