Security Questionnaire Mapper
Governance and policy ยท question family

Security roles and a named security lead: the clause the question tests

Whether a named person owns security, and to whom they report.

How the customer usually asks it

example

"Who is responsible for information security in your organisation?"

Read this question

Anchor clauses

1 framework
FrameworkAnchor clause
ISO/IEC 27001:20225.2 Information security roles and responsibilities

Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.

Evidence expected

An organisation chart or role description naming who owns information security, the reporting line, and the roles below it.

The clauses, with what an assessor asks for

ISO 27001 5.2 Information security roles and responsibilities

Name who owns what in security and make the allocation explicit and traceable.

Evidence an assessor expects: Role definitions; Responsibility matrix; Assignment records; Authority delegation
Where answers usually fall short: Roles not updated after staff changes; No documented acceptance of responsibilities
Source: ISO/IEC 27001:2022

Other families in governance and policy