5.3 Organizational Roles, Responsibilities, and Authorities
Top management ensures that information security roles, responsibilities, and authorities are clearly assigned, documented, and communicated across the organization. This framework ensures the ISMS conforms to ISO/IEC 27001 requirements and that security performance is reported accurately to leadership.
5.3.1 RACI Governance Matrix
The following table defines the assignment of roles and responsibilities regarding the ISMS.
| Role | Plan | Do / Act | Study |
|---|---|---|---|
| Director | I | A | I |
| Management Team | R | R | R |
| Operations Manager | R | R | R |
| Business Manager | R | R | R |
| Internal Auditor (RA) | - | - | R |
| All Staff | C | R | - |
- R (Responsible): Performs the work.
- A (Accountable): Ultimately answerable for completion and sign-off.
- C (Consulted): Subject-matter experts providing input.
- I (Informed): Kept up-to-date on progress.

5.3.2 Roles and Authorities
Director
The Director is Accountable for the ISMS and all associated policies. Responsibilities include:
- Adopting budgets for security improvement plans.
- Final approval of policy documents, risk assessments, and treatment plans.
- Ensuring all employees and contractors are aware of and comply with established security policies.
- Overseeing incident response and business continuity decisions in alignment with A.05.29 - Information security during disruption and A.05.30 - ICT readiness for business continuity.
- Reviewing performance via annual Security Management Reports and bi-monthly ISMB meetings.
Management Team (MT)
The MT is Responsible for the effective application of the ISMS and policy enforcement. Key duties include:
- Fulfilling the role and responsibilities of a Security Officer
- Coordinating security awareness campaigns and policy development.
- Overseeing data breach resolution, processing registers, and incident analysis.
- Managing internal and external audits.
- Supervising and coordinating activities delegated to specific asset owners.
Functional Managers (Operations & Business)
Reporting to the Director, these roles are Responsible for:
- Providing input for policy and risk analysis.
- Executing and assessing ICT, HR, and Financial Administration projects.
- Ensuring operational procedures align with security policy within their respective domains.
Asset Responsibles
The "daily" responsibility for compliance rests with designated asset responsibles. They supervise adherence to established procedures, guidelines, and security controls within their specific operational areas.
All Employees and Contractors
Every individual at anDREa is Responsible for maintaining a security-conscious mindset. This includes:
- Adhering strictly to established procedures.
- Promptly reporting security incidents or anomalies.
- Protecting confidential or sensitive data entrusted to them.