Back to all 93 controls
Annex A 5.2
Organizational
A.5.2 Information security roles and responsibilities
Clear ownership of information security.
What good looks like
Roles for ISMS owner, control owners, risk owners and incident response are defined and assigned.
Evidence an auditor will ask for
RACI matrix, org chart, job descriptions, appointment letters.
Put this control into practice
Check whether your organisation already meets Annex A 5.2 with the free Gap Analysis tool, or get implementation-ready templates for every Annex A control with the Document Pack.
