Governance and policy ยท question family
Security roles and a named security lead: the clause the question tests
Whether a named person owns security, and to whom they report.
How the customer usually asks it
example"Who is responsible for information security in your organisation?"
Anchor clauses
1 framework| Framework | Anchor clause |
|---|---|
| ISO/IEC 27001:2022 | 5.2 Information security roles and responsibilities |
Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.
Evidence expected
An organisation chart or role description naming who owns information security, the reporting line, and the roles below it.
The clauses, with what an assessor asks for
ISO 27001 5.2 Information security roles and responsibilitiesName who owns what in security and make the allocation explicit and traceable.
Evidence an assessor expects: Role definitions; Responsibility matrix; Assignment records; Authority delegation
Where answers usually fall short: Roles not updated after staff changes; No documented acceptance of responsibilities
Source: ISO/IEC 27001:2022
Where answers usually fall short: Roles not updated after staff changes; No documented acceptance of responsibilities
Source: ISO/IEC 27001:2022