GOV-002 Information Security Roles and Responsibilities
Description
Information security roles and responsibilities are defined, documented, and allocated to named individuals or functions. This includes a named owner for the information security programme, ownership assignments for information assets, and documented accountability for key security decisions.
Rationale
Without defined ownership and accountability, security controls are unenforceable and audits cannot confirm that obligations are being met.
Applicability (9 profiles)
164.308(a)(2) asks for one named security official responsible for developing and implementing the policies and procedures of the subpart. The named programme owner GOV-002 already requires is that person, and under this overlay the name has to be producible on request rather than merely assigned.
Annex point 1.2.3 requires at least one person to report directly to the management bodies on network and information system security, which is a line rather than a role. Point 1.2.2 extends the duty to apply the security policies to third parties as well as personnel, and point 1.2.6 has the management bodies review the allocation on interval and on significant incidents or changes.
Framework Mappings (10)
| GRC-06 | Governance Responsibility Model | full |
| GRC-06 | Governance Responsibility Model | full |
| HIPAA-164.308.a.2 | Assigned Security Responsibility | full |
| 5.2 | Information security roles and responsibilities | full |
| NIS2-CIR-1.1 | Policy on the Security of Network and Information Systems | informative |
| NIS2-CIR-1.2 | Roles, Responsibilities and Authorities | partial |
| PM-2 | Information Security Program Leadership Role | full |
| PM-29 | Risk Management Program Leadership Roles | partial |
| GOVERN 2.1 | AI Risk Roles and Responsibilities | informative |
| CC1.3 | COSO Principle 3: Establishes Structure, Authority, and Responsibility | partial |
Evidence (2)
Documented information security roles and responsibilities matrix or RACI, assigning ownership to named individuals or job functions.
Example: Security Roles and Responsibilities document or RACI matrix (Confluence/Google Drive), listing the named CISO or security programme owner, asset owners, and accountability for key security decisions.
Test: Request the roles and responsibilities document. Verify: (1) a named individual or titled role is designated as security programme owner, (2) asset ownership is assigned for at least the critical information assets in the asset inventory, (3) the document has an approval date and named approver.
Decision records showing the named information security programme owner exercising the accountability the roles document assigns.
Example: Approved policy exception GOV-EX-2026-014 and risk acceptance RA-2026-007, each carrying the signature of the named security programme owner, March and June 2026
Test: Request the roles document and the decisions taken under it in the last 12 months. Verify: (1) the roles document names an owner for the information security programme and an owner for each critical information asset, (2) at least one decision reserved to the programme owner in the period carries that person's recorded approval, (3) the approver named on each such decision holds the role the document assigns it to, (4) a decision taken while the role was vacant carries a recorded interim owner, (5) no decision reserved to the role was taken by someone outside it without a recorded delegation.
Questions (2)
Are information security roles and responsibilities formally documented and assigned to named individuals or functions?
Look for a roles-and-responsibilities document or RACI that names a security programme owner and assigns asset ownership for critical information assets.
Which of the following security ownership roles are formally defined and filled in your organisation?
At a minimum, a named security programme owner and asset owners for critical systems should be documented and verifiable against the org chart.