GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

GOV-002 Information Security Roles and Responsibilities

Tier 1+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Information security roles and responsibilities are defined, documented, and allocated to named individuals or functions. This includes a named owner for the information security programme, ownership assignments for information assets, and documented accountability for key security decisions.

Rationale

Without defined ownership and accountability, security controls are unenforceable and audits cannot confirm that obligations are being met.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
HIPAA Business Associate (US)stablerequiredrole duty

164.308(a)(2) asks for one named security official responsible for developing and implementing the policies and procedures of the subpart. The named programme owner GOV-002 already requires is that person, and under this overlay the name has to be producible on request rather than merely assigned.

NIS2 Cloud Provider (EU)stablerequiredrole duty

Annex point 1.2.3 requires at least one person to report directly to the management bodies on network and information system security, which is a line rather than a role. Point 1.2.2 extends the duty to apply the security policies to third parties as well as personnel, and point 1.2.6 has the management bodies review the allocation on interval and on significant incidents or changes.

Framework Mappings (10)

GRC-06Governance Responsibility Modelfull
GRC-06Governance Responsibility Modelfull
HIPAA-164.308.a.2Assigned Security Responsibilityfull
5.2Information security roles and responsibilitiesfull
NIS2-CIR-1.1Policy on the Security of Network and Information Systemsinformative
NIS2-CIR-1.2Roles, Responsibilities and Authoritiespartial
PM-2Information Security Program Leadership Rolefull
PM-29Risk Management Program Leadership Rolespartial
GOVERN 2.1AI Risk Roles and Responsibilitiesinformative
CC1.3COSO Principle 3: Establishes Structure, Authority, and Responsibilitypartial

Evidence (2)

policydocumentmanual

Documented information security roles and responsibilities matrix or RACI, assigning ownership to named individuals or job functions.

Example: Security Roles and Responsibilities document or RACI matrix (Confluence/Google Drive), listing the named CISO or security programme owner, asset owners, and accountability for key security decisions.

Test: Request the roles and responsibilities document. Verify: (1) a named individual or titled role is designated as security programme owner, (2) asset ownership is assigned for at least the critical information assets in the asset inventory, (3) the document has an approval date and named approver.

recorddocumentmanual

Decision records showing the named information security programme owner exercising the accountability the roles document assigns.

Example: Approved policy exception GOV-EX-2026-014 and risk acceptance RA-2026-007, each carrying the signature of the named security programme owner, March and June 2026

Test: Request the roles document and the decisions taken under it in the last 12 months. Verify: (1) the roles document names an owner for the information security programme and an owner for each critical information asset, (2) at least one decision reserved to the programme owner in the period carries that person's recorded approval, (3) the approver named on each such decision holds the role the document assigns it to, (4) a decision taken while the role was vacant carries a recorded interim owner, (5) no decision reserved to the role was taken by someone outside it without a recorded delegation.

Questions (2)

boolean

Are information security roles and responsibilities formally documented and assigned to named individuals or functions?

Look for a roles-and-responsibilities document or RACI that names a security programme owner and assigns asset ownership for critical information assets.

multi

Which of the following security ownership roles are formally defined and filled in your organisation?

Named CISO or security programme ownerInformation asset owners for critical assetsData protection / privacy leadSecurity team with documented responsibilitiesNone of the above

At a minimum, a named security programme owner and asset owners for critical systems should be documented and verifiable against the org chart.