Organisational Roles, Responsibilities and Authorities for ISO 27001 Information Security

ISO 27001 Clause 5.3

This sub-clause requires top management to assign and communicate roles, responsibilities and authorities relevant to the ISMS.

ISO 27001 Clause 5.3 - Organisational Roles, Responsibilities and Authorities

Clause 5.3 closes out the leadership clauses by making sure responsibility for the information security management system is properly assigned. It is short - one paragraph in the standard - but it has implications across the whole system. Without clear roles, the policy commitments and risk treatments do not get implemented.

What ISO 27001 Clause 5.3 Requires

Top management must assign the responsibilities and authorities for roles relevant to information security and communicate them within the organisation. The standard also calls out two specific responsibilities top management must assign: making sure the ISMS conforms to the requirements of ISO 27001, and reporting on the performance of the ISMS to top management.

The clause does not mandate a specific role title or organisational structure. Some organisations have a dedicated information security manager. Others give the role to the IT manager or the data protection officer. Smaller organisations might combine it with other management responsibilities. The structure is for the organisation to decide, but the responsibilities have to be defined and communicated.

Common Roles Within an ISO 27001 ISMS

Most ISMS structures include some combination of the following roles. Top management sets direction, approves the policy, allocates resources and reviews performance. The information security manager or equivalent runs the system day to day, including the risk assessment, controls implementation and reporting. Asset owners are accountable for the information and systems they own. Risk owners are responsible for the treatment decisions on specific risks. Internal auditors independently check that the system is working.

Where the organisation is small, several of these roles can sit with the same person, provided the conflicts of interest are managed. The internal auditor must be independent of the activities being audited, which means the person who runs the controls cannot be the person who audits them.

Documenting and Communicating the Roles

Roles and responsibilities are most often documented in the management system manual, in role descriptions, in policies and in the organisation chart. The communication needs to reach the people who hold the roles and the people who interact with them. Job descriptions, induction materials and the intranet are typical channels.

The clause does not need a complicated org chart. It needs the people who hold ISMS roles to know what they are responsible for, and it needs everyone else to know who to ask when they have a question. A short list of roles in the manual is usually all that is required.

I check Clause 5.3 by asking whoever holds the information security role to explain what they are responsible for. I then ask their boss the same question. If the answers line up, the clause is being met. If they do not line up, there is a gap that needs closing before the audit moves on.

Practical Compliance Guidance

Roles and responsibilities for the ISMS are typically captured in the IMS1 Integrated Management System Manual, where they sit alongside the system overview and the policy.

The documents below support the assignment and communication of ISMS roles and responsibilities.

alphaZ document How to use it
ISO 27001 Toolkit Complete documentation set for ISO 27001:2022 including the IMS1 Manual where roles and responsibilities are defined.
A-C ISO 9001 - 27001 Management System Audit Checklist Audit checklist covering the management system clauses including the evidence needed for Clause 5.3 roles and responsibilities.

Note - all the above files can be downloaded with an alphaZ subscription.

Frequently Asked Questions

No. The standard does not require any specific job title. It requires the responsibilities for information security to be assigned and communicated. Smaller organisations often combine the role with another management role. Larger ones may have a dedicated CISO.
Not for audits of activities they are responsible for. The internal auditor needs to be independent of the activity being audited. In a small organisation, this often means using an external internal auditor or splitting the audit programme so that team members audit each other's areas.
An asset owner is accountable for an information asset - typically a system, dataset or application. A risk owner is accountable for the treatment of a specific risk. They are often the same person, but not always. The risk owner is the one who approves the residual risk after treatment.

UK Legislation

UK GDPR creates a legal requirement for some organisations to appoint a Data Protection Officer, which often overlaps with the information security role. The relevant legislation is below.

Further Resources

payment logos