# Information security roles and responsibilities

Source: https://aestech.com.au/policy-templates/#information-security-roles-and-responsibilities
Markdown URL: https://aestech.com.au/policy-templates/information-security-roles-and-responsibilities.md

Use for ISO 27001 A.5.2, A.5.3 and A.5.4, defining security roles, segregation of duties, management responsibilities, and SOC 2 organisational controls.

Frameworks: ISO 27001, SOC 2

Use this as a starting point only. Adapt it to your real scope, systems, legal obligations, customer commitments and operating process.

```text
1. Purpose
This policy defines and allocates information security roles so that every security responsibility has a named, accountable owner, conflicting duties are separated, and staff know who decides, who does the work and who must be informed.

2. Scope
This policy applies to all employees, contractors and governance bodies of [Company Pty Ltd], and covers all activities within the ISMS scope.

3. Policy statements
- Every control, asset, risk and policy in the ISMS must have a named owner recorded in [ISMS register]. Ownership follows the role, not the person, and transfers automatically on role change.
- Duties must be segregated so that no single person can request, approve and implement the same high-risk change, or grant themselves privileged access. Where headcount makes separation impractical, [compensating monitoring or independent review] must be documented and approved by [role].
- Security responsibilities must be stated in employment contracts, position descriptions and supplier agreements.

4. Roles and responsibilities
- [CEO or managing director]: ultimately accountable for information security; approves the information security policy, risk appetite and ISMS resourcing; is informed of all SEV1 incidents.
- [CISO or security lead]: accountable for operating the ISMS; runs risk assessments, coordinates internal audits and management reviews, reports ISMS performance to leadership at least [quarterly], and is the escalation point for security decisions.
- Asset owners: accountable for the protection of their assets; approve access, set classification, and accept or escalate risks affecting their assets.
- Risk owners: accountable for individual risks in the [risk register]; decide treatment, track actions to closure and formally accept residual risk within delegated limits.
- [IT lead or system administrators]: responsible for implementing technical controls, provisioning approved access and maintaining logging and backups; consulted on all changes affecting security.
- Managers: responsible for ensuring their teams complete training, follow policies and report events; consulted on role changes affecting access.
- All staff: responsible for following policies, protecting information they handle and reporting suspected security events immediately; informed of policy changes through [channel].

5. Procedures
- Escalation path: staff report to their manager or [security contact]; the [security lead] escalates to [CEO] for SEV1 incidents, risk acceptances above [threshold] and legal notification decisions.
- The role register is updated within [5] business days of any appointment, departure or restructure.
- Deputies are named in [register] for the [security lead] and each asset owner to cover absence.

6. Evidence and records
Keep the role and ownership register, signed position descriptions, delegation and deputy records, segregation of duties matrix, risk acceptance records, management review minutes and escalation records.

7. Review
Owner: [role]. Reviewed at least annually, after organisational changes and after any audit finding on accountability.
```

Full template pack: https://aestech.com.au/policy-templates/policy-pack.md