A.5.2Information security roles and responsibilities
Assign and document who is responsible for what in information security, so every protection task has a clear owner. Avoid gaps and overlaps by mapping responsibilities to named roles or people.
Mapping at a glance
A.5.2Information security roles and responsibilitiesISO/IEC 27001:2022
What an auditor, or Sekit's evidence engine, asks for.
Security roles and responsibilities
The document or chart showing who owns each aspect of security in the company (e.g. a security org chart or a RACI matrix).
From the Sekit evidence catalog
In practice
In a small company this control usually lives as a short table: who owns security overall, who owns incident response, who owns access reviews, mapped to named people rather than job titles that might change. Auditors check the security roles and responsibilities document against the org chart and ask a named owner directly what their duties involve; a mismatch between the document and what the person can describe is the most common finding. The usual failure is a security officer title given to someone with no time carved out for the role, so the duties exist on paper but nobody performs them.
Common gaps
The named security owner changed roles or left the company months ago and the roles document was never updated to reflect who holds the responsibility now.
Responsibilities are described at a general level, such as 'IT manages security', without naming which specific duties, like access reviews or incident triage, that role owns.
The person assigned a security duty was never told about it and cannot describe what the responsibility involves when asked directly.
Questions your auditor will ask
Who is accountable for information security in this organization, and how is that documented?
Point to the security roles and responsibilities document, naming the accountable individual and the date the assignment was last confirmed.
How do you avoid gaps or overlaps between roles?
Show the responsibilities mapped one duty at a time to a single named owner, so each recurring security task has one person accountable for it.
Does the named owner perform their assigned duties on a regular basis?
Provide evidence the duty is exercised on a verifiable rhythm, such as a signed access review log or incident response drill record tied to that person's name.
What happens to a role's responsibilities when that person leaves?
Describe the handover step in the offboarding process that reassigns the departing person's security duties to a named successor before their last day.
Where regulation demands it
NIS2 art. 1.2 (Roles, responsibilities and authorities) requires the same mapping of security duties to named, accountable people.
ENS mp.per.1 (Caracterización del puesto de trabajo) requires each post to have its security responsibilities defined, the same accountability mapping A.5.2 documents.
Related controls
Via the shared Sekit CSF topic, not the framework's own index.