A.5.2 Information security roles and responsibilities
1. Allocation Based on Organizational Needs
anDREa defines and allocates specific information security roles and responsibilities to ensure alignment with our corporate structure, operational complexity, and the cloud-native architecture of the myDRE platform. As established in Clause 4 - Context of the Organisation, our resource allocation scales alongside our operational footprint to ensure all technical and administrative security controls have clear ownership.
The structural blueprint mapping specific security tasks to organizational functions is explicitly detailed and maintained within the anDREa Roles and Responsibilities Matrix. This framework assigns ownership across all departments and levels of the company, eliminating gaps in control execution and incident escalation.
2. Maintenance and Dynamic Review Loops
The Roles and Responsibilities Matrix is treated as a dynamic governance document rather than a static organizational chart. To satisfy ISO/IEC 27001 Annex A.5.2, the Management Team ensures its ongoing accuracy through the following review mechanisms:
- Periodic Evaluation: The matrix undergoes a formal, scheduled review at planned intervals to confirm that resource assignments match active business requirements.
- Structural Triggers: An ad-hoc evaluation and update loop are automatically triggered when any of the following events occur:
- Material shifts in organizational size, structural hierarchy, or staff composition.
- Significant technological developments, such as updates to the core cloud infrastructure or the onboarding of new automation tooling.
- Shifts in the macro threat landscape or the emergence of sophisticated cyber threats requiring specialized monitoring or remediation roles.
3. Core Information Security Responsibilities
While granular task mappings are maintained inside the master matrix, primary information security expectations are allocated across the following baseline profiles:
- The Director (Top Management): Retains ultimate accountability for the corporate risk appetite, signs off on policy changes, and ensures sufficient resource allocation to sustain the ISMS.
- The Management Team (Acting Security Officer): As of April 2025, the Management Team collectively carries out all operational Security Officer responsibilities. This includes triaging security incidents, driving risk assessments, executing the internal audit program, and validating policy effectiveness.
- The Scrum Master & Engineering Team: Responsible for implementing technical security parameters, secure development lifecycle practices (DevSecOps), and resolving security-related Product Backlog Items (PBIs).
- All Employees and Contractors: Mandated to maintain security awareness, report suspected anomalies or policy deviations immediately, and adhere strictly to active policy guidelines (see: ISMB - Meeting Notes).