Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Director

previous version on gdrive

N.1.03 Assignment of responsibility for cybersecurity

Control Overview

This control mandates the clear definition, allocation, and documentation of cybersecurity roles and responsibilities across the entire organization. To prevent security incidents caused by operational gaps, delays, or a lack of ownership, accountability must be explicitly assigned. The control requires that at least one individual is designated with ultimate responsibility for organizational cybersecurity, and that those empowered to initiate and decide on security measures are clearly known. Furthermore, these roles must be communicated to all staff and regularly reviewed to align with evolving organizational structures, technologies, and threat landscapes.

note

Applicability Note: This control is fully applicable to the anDREa platform and its management structure.

Compliance & Strategic Approach

Our approach integrates these ownership requirements directly into our ISO/IEC 27001-based ISMS, avoiding isolated silos and embedding cybersecurity into our corporate governance.

Accountability is driven directly from the top. Rather than isolating security to a single operational pocket, the Management Team collectively fulfills the Security Officer role, with the Director holding ultimate accountability. This structure provides the necessary executive mandate to enforce compliance and respond proactively to incidents. Day-to-day duties, operational boundaries, and segregation of duties (to prevent toxic combinations of privileges) are codified in a centralized matrix. This matrix undergoes continuous evaluation alongside our risk cycles to maintain relevance.


Control Mappings & Evidence

Framework / Document ReferenceElement & IdentifierDescription / Relationship to NIS 2
ISO/IEC 27001Clause 5 - LeadershipEstablishes the executive mandate, defining management's collective ownership and ultimate accountability for the ISMS.
ISO/IEC 27001Clause 5.2 - PolicyGoverns the formal definition, assignment, and communication of information security roles across all personnel layers.
ISO/IEC 27001Clause 5.3 - Organisational roles, responsibilities and authoritiesEnforces the separation of conflicting responsibilities to mitigate internal risk and document necessary mitigating controls.
Core Governance MatrixanDREa Roles & Responsibilities MatrixThe definitive organizational directory detailing specific cybersecurity tasks, ownership, and the explicit designation of the "responsible manager."

Includes ormal declarations affirming that the Management Team collectively acts as the Security Officer, led by the Director.

Audit Summary

  • Compliance Status: Fully Compliant
  • Gaps Identified: None. The explicit designation of a responsible manager, clear segregation of duties, and management-level accountability are fully operationalized and documented.