ISO/IEC 27000 Information Security Roles and Responsibilities, v2022
Specifies requirements in accordance with the security and privacy controls specified by ISO/IEC Publication 27001:2022, related to information security roles and responsibilities.
Assessment Step
1
Information Security Roles and Responsibilities (InformationSecurityRolesandResponsibilities)
Does the organization define and allocate information security roles and responsibilities according to its organizational needs?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Information Security Roles and Responsibilities
Information security roles and responsibilities shall be defined and allocated according to the organization needs.
Citations
27001
Annex A, Control 5.2
27002
Section 5.2
|