ISO 27001A.5 — Information security roles and responsibilities
A.5.2
Information security roles and responsibilities
ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026
Objective
Assign and communicate information security roles and responsibilities so accountability for ISMS outcomes is clear.
Points of focus
- Define scope and requirements for information security roles and responsibilities
- Assign ownership and operating cadence
- Integrate with risk treatment and SoA status
- Retain dated records proving operation
Implementation notes
Name owners for ISMS processes — risk, SoA, access, incident — and make sure deputies exist so certification does not depend on one person. Tie the SoA implementation summary to the systems of record engineers already use, and keep dated samples ready for Stage 2 sampling.
Audit tip: Present the SoA line for A.5.2, the current procedure, and one recent dated operating sample with a named owner.
Evidence auditors typically request:
- Approved information security policy set with version and owner
- Statement of Applicability entry with applicability rationale
- Management review minutes referencing the control theme
- Ticket or register samples showing the process operated
Common gaps
- SoA marks information security roles and responsibilities applicable without dated operating samples
- Procedure exists but interviews describe a different tribal process
- Owner unclear or last review older than the stated cadence
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.5.2 | This control |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.5.2)
Frequently Asked Questions
Applicability depends on risk and scope. Many cloud-native SoAs still include organizational and technological controls; physical themes may be partially inherited from providers with documented shared responsibility.
Applicability decision, brief implementation summary, and justification if excluded. Vague 'N/A — cloud' without rationale is a common Stage 1 finding.
Name the owner, the system of record, and the cadence. Auditors sample reality — tickets, configs, and interviews — not synonym-rewritten ISO text.