A.5.2A.5 Organizational controls

Information security roles and responsibilities

A.5EVIDENCEA.6EVIDENCEA.7EVIDENCEA.8EVIDENCECONTROL MAPA.5.2 Evidence MapPOLICY / CONTROL / EVIDENCE / REVIEW

Purpose

Set up a clear, approved and understood structure for running and managing information security across the organisation.

How to meet this control

In short: Define and allocate security responsibilities according to the organisation’s needs.

  1. Step 01Produce a RACI matrix mapping every Annex A control and ISMS task to a named role, so each control has one accountable owner
  2. Step 02Capture security duties in formal position descriptions and the appointment letter for the CISO or security manager
  3. Step 03Define and document delegated authority limits (for example who can approve access, accept risk or authorise an emergency change)
  4. Step 04Brief asset and risk owners on their specific obligations and confirm acceptance in writing
  5. Step 05Review the role allocation whenever the org structure changes and at least annually alongside the policy review

Tip: Maintain a simple RACI so every control has a named owner.

What ISO 27002 says to cover

Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.

  • ›Define and allocate security roles and responsibilities in line with the security policies
  • ›Assign responsibility for protecting assets, running security processes and managing security risks
  • ›Name owners who accept residual risk, such as risk owners for specific risk areas
  • ›Document and communicate each area of responsibility along with the authority levels that apply
  • ›Allow tasks to be delegated while keeping the original role holder accountable for correct completion
  • ›Ensure people in security roles have the right skills and stay up to date with relevant developments
  • ›Consider appointing a security manager for overall coordination and asset owners for day-to-day protection

Audit evidence to keep

  • - RACI matrix or responsibility assignment register mapping controls to named owners
  • - Position descriptions or appointment letters citing information security responsibilities
  • - Documented delegation-of-authority schedule with approval thresholds
  • - Records of risk and asset owners formally accepting their responsibilities

Common mistakes

  • - Writing a policy but not operating the process
  • - Keeping evidence in personal folders where auditors cannot trace it
  • - Letting exceptions stay open with no owner or expiry date

Owner, cadence, and proof

Assign one accountable owner for A.5.2. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Back to all organizational controls or see the requirements (clauses 4 to 10). To run this control with automation, read how AI manages controls.