ISMS Roles, Responsibilities and Authorities
In ISO/IEC 27001:2022, clause 5.3 (Organizational roles, responsibilities and authorities) requires top management to ensure that responsibilities and authorities for roles relevant to information security are assigned and communicated within the organization. This clause sits under Leadership (cla… In ISO/IEC 27001:2022, clause 5.3 (Organizational roles, responsibilities and authorities) requires top management to ensure that responsibilities and authorities for roles relevant to information security are assigned and communicated within the organization. This clause sits under Leadership (clause 5), which shows that accountability for the ISMS cannot be delegated away entirely. Top management keeps ultimate accountability, even when operational tasks are assigned to others. The standard explicitly requires top management to assign responsibility and authority for two things. First, ensuring that the ISMS conforms to the requirements of ISO/IEC 27001. Second, reporting on the performance of the ISMS to top management. These tasks are often given to an ISMS Manager or CISO, but the standard does not prescribe job titles. An organization may assign them to one person, a committee, or several functions, depending on its size and complexity. Other clauses define further roles. Clause 6.1.2 requires the identification of risk owners, who are accountable for managing specific risks and for approving risk treatment plans and the acceptance of residual risk. Annex A control 5.2 addresses information security roles and responsibilities more broadly. Control 5.3 requires segregation of conflicting duties. Control 5.4 requires management to ensure that personnel apply security in line with policy. Clause 7.2 adds that people in these roles must be competent, and clause 7.3 requires that they are aware of their contribution to the ISMS. From a Lead Auditor perspective, auditors seek objective evidence that roles are clearly defined, documented where necessary, communicated, and understood. Typical evidence includes: - organization charts - job descriptions - appointment letters - RACI matrices - ISMS committee terms of reference - interview results Auditors check that the assigned people actually hold the necessary authority and resources. They also check that reporting to top management really happens, for example through management review records under clause 9.3. Common nonconformities include: - undefined risk ownership - responsibilities that exist only on paper - conflicting duties without compensating controls - staff who are unaware of their security responsibilities
ISMS Roles, Responsibilities and Authorities (ISO/IEC 27001 Clause 5.3): A Lead Auditor Guide
Introduction
An Information Security Management System (ISMS) fails if nobody clearly owns it. ISO/IEC 27001:2022 Clause 5.3, Organizational roles, responsibilities and authorities, makes sure the right people are assigned to run, maintain, monitor and report on the ISMS. They must also know they have been assigned, and they must have the authority to act. For an ISO 27001 Lead Auditor, this clause links leadership intent (Clause 5.1) to day-to-day operation. It is also a common source of scenario-based exam questions.
1. Why ISMS Roles, Responsibilities and Authorities Matter
Accountability and ownership: Without defined roles, security tasks fall between departments. Examples include risk assessments, access reviews, incident handling and supplier checks. When everyone assumes someone else is responsible, no one is.
Effective decision-making: Authority lets people act. For example, they can stop a non-compliant change, escalate an incident, approve risk treatment or allocate budget. Responsibility without authority leads to frustration and inaction.
Leadership commitment in practice: Clause 5.1 requires top management to demonstrate leadership. Assigning and communicating roles is one of the most visible, auditable ways they do this.
Risk management integrity: Clause 6.1.2 c) requires risk owners to be identified. Clause 6.1.3 f) requires risk owners to approve the risk treatment plan and accept residual risks. Neither works without defined roles and authorities.
Performance reporting: Top management cannot review the ISMS effectively (Clause 9.3) unless someone is assigned to report on its performance.
Prevention of conflicts of interest: Clear role definition supports Annex A control 5.3, Segregation of duties. This reduces the risk of fraud, error and misuse.
Certification readiness: Auditors routinely sample people and ask: 'What is your role in information security?' Unclear answers often lead to findings.
2. What the Requirement Says
Clause 5.3 of ISO/IEC 27001:2022 requires that:
• Top management shall ensure that the responsibilities and authorities for roles relevant to information security are assigned and communicated within the organization.
• Top management shall assign the responsibility and authority for:
a) ensuring that the ISMS conforms to the requirements of ISO/IEC 27001; and
b) reporting on the performance of the ISMS to top management.
• A Note clarifies that top management may also assign responsibilities and authorities for reporting performance of the ISMS within the organization.
Key words to remember:
• Responsibility: the obligation to perform a task or achieve an outcome.
• Authority: the power to make decisions, allocate resources or direct others in order to fulfil that responsibility.
• Accountability: remains with top management. They can delegate responsibility and authority, but not ultimate accountability for the ISMS (see Clause 5.1).
• Assigned: roles must be formally given to individuals or functions, not just implied.
• Communicated: the people concerned, and others who need to know, must be aware of the assignments.
What the clause does NOT require:
• It does not require a specific job title such as CISO, ISMS Manager or Information Security Officer. Any suitably competent person or function can hold the role.
• It does not explicitly mandate documented information. However, organizations usually document roles, and auditors need evidence. Annex A 5.2 and Clause 7.5 (documented information determined necessary by the organization) mean documentation is the normal and expected practice.
• It does not require a full-time dedicated role. Small organizations may combine roles, provided conflicts of interest are managed.
Related clauses and controls (2022 edition):
• Clause 5.1 Leadership and commitment: top management accountability.
• Clause 5.2 Policy: the information security policy is communicated, and it often defines roles.
• Clause 6.1.2 / 6.1.3 Risk owners: identification, approval of the treatment plan and acceptance of residual risk.
• Clause 7.1 Resources and Clause 7.2 Competence: people in roles must be competent.
• Clause 7.3 Awareness: people must know their contribution to the ISMS.
• Clause 7.4 Communication: who communicates what, to whom and when.
• Clause 9.3 Management review: receives performance reports.
• Annex A 5.2 Information security roles and responsibilities: defined and allocated according to organizational needs.
• Annex A 5.3 Segregation of duties.
• Annex A 5.4 Management responsibilities: management requires all personnel to apply security according to policy.
• Annex A 5.9 / 5.10 Asset ownership and acceptable use.
• Annex A 6.2 Terms and conditions of employment: security responsibilities in contracts.
• Annex A 5.19 to 5.22 Supplier relationships: responsibilities extend to external parties.
3. How It Works in Practice
Step 1 – Identify the roles relevant to information security. Typical roles include:
• Top management or executive sponsor: ultimate accountability, approves policy, provides resources, chairs or attends management review.
• ISMS Manager or Information Security Manager: ensures conformity to ISO 27001 and reports performance (the two mandatory assignments in 5.3 a and b).
• Information Security Steering Committee or Forum: cross-functional oversight and decision-making.
• Risk owners: accept and own specific risks, approve treatment.
• Asset owners: manage classification, access and protection of assets.
• Control owners: operate and monitor specific Annex A controls.
• IT and operations teams: implement technical controls.
• HR: screening, onboarding, disciplinary process, awareness.
• Legal and compliance: legal, regulatory and contractual requirements.
• Internal auditor(s): independent audits (Clause 9.2). They must be objective and impartial.
• Incident response team: detection, response and lessons learned.
• Data Protection Officer, where applicable: privacy interface.
• All employees and contractors: follow policy and report events (Annex A 6.8).
Step 2 – Define responsibilities and authorities. Use tools such as:
• Job descriptions and role profiles that include security duties.
• RACI matrices (Responsible, Accountable, Consulted, Informed).
• Terms of reference for committees.
• Organization charts showing reporting lines.
• Delegation of authority matrices, such as approval limits and the authority to suspend access.
Step 3 – Formally assign. Examples include appointment letters, board or management minutes, signed role acceptance, contract clauses and policy statements naming roles.
Step 4 – Communicate within the organization. Examples include intranet publication, the policy manual, induction training, awareness sessions, team briefings and published contact lists (such as who to call in an incident).
Step 5 – Ensure competence and resources. Clause 7.2 requires the people assigned to be competent on the basis of education, training or experience. Clause 7.1 requires that they have adequate resources, such as time, budget and tools.
Step 6 – Monitor, review and update. Roles change with reorganizations, staff turnover, outsourcing and new technologies. Role definitions should be reviewed periodically and whenever significant changes occur (see Clause 6.3, Planning of changes).
Example of good practice:
A mid-sized software company appoints its Head of IT Security as ISMS Manager through a CEO letter. The letter states that the ISMS Manager is responsible for ISO 27001 conformity and for presenting a quarterly ISMS performance report to the executive team. It also grants authority to halt deployments that bypass change control. A RACI matrix in the ISMS manual lists risk owners for each risk category. All staff learn about the structure at induction, and it is published on the intranet. The ISMS Manager completed lead implementer training, and the record is held by HR.
4. What a Lead Auditor Looks For
Documents and records:
• Organization chart and ISMS structure.
• Appointment letters or minutes assigning the ISMS conformity and performance-reporting roles.
• Job descriptions with security responsibilities.
• RACI matrix, risk register showing risk owners, asset inventory showing asset owners.
• Committee terms of reference and meeting minutes.
• Competence records for key role holders.
• Management review inputs showing performance reports were delivered.
Interview questions an auditor might ask:
• To top management: 'Who have you made responsible for ensuring the ISMS conforms to ISO 27001? How do they report to you?'
• To the ISMS Manager: 'What authority do you have if a department refuses to implement a control?'
• To a risk owner: 'Which risks do you own? Did you approve the treatment plan and accept the residual risk?'
• To a staff member: 'What are your information security responsibilities? Who would you report a security incident to?'
Typical nonconformities related to Clause 5.3:
• No one has been assigned responsibility for reporting ISMS performance to top management.
• The ISMS Manager has responsibility but no authority. For example, they cannot enforce controls or access the resources needed.
• Roles exist on paper but the role holders are unaware of them (not communicated).
• Roles are assigned to people who have left the organization (not kept up to date).
• Risk owners are not identified, or are identified only as 'IT' with no accountable individual. This also links to 6.1.2.
• Conflicting roles, such as an internal auditor auditing their own work, or one person both requesting and approving privileged access without compensating controls.
• Outsourced or third-party security responsibilities are not defined.
Grading findings:
• Major nonconformity: a total absence or systemic failure. Examples: no assignment at all of the 5.3 a) and b) responsibilities, or a complete breakdown where no one manages the ISMS.
• Minor nonconformity: an isolated lapse. Examples: one job description missing security duties, or one role holder unaware of an assignment while the overall system works.
• Opportunity for improvement: the requirement is met but could be strengthened. An example is consolidating role definitions into a single RACI matrix.
5. Exam Tips: Answering Questions on ISMS Roles, Responsibilities and Authorities
Tip 1 – Know the exact wording. Remember the three verbs: ensure, assign, communicate. Also remember the two mandatory assignments: conformity of the ISMS and reporting performance to top management. Many multiple-choice questions test whether you can recognize these two specific items.
Tip 2 – Top management is the subject of the clause. It is top management, not the ISMS Manager, the HR department or the consultant, who must ensure roles are assigned and communicated. If an option says 'the ISMS Manager shall assign roles', it is usually a distractor.
Tip 3 – Distinguish responsibility from accountability. Responsibility and authority can be delegated. Accountability for ISMS effectiveness stays with top management (Clause 5.1). Exam questions often test this distinction.
Tip 4 – No specific title or structure is mandated. If a question asks whether a nonconformity exists because there is no CISO, the answer is no, provided the responsibilities are assigned to someone. ISO 27001 is outcome-based, not prescriptive about titles.
Tip 5 – Responsibility without authority is a finding. In scenarios where the security manager 'cannot enforce', 'has no budget' or 'is overruled without process', look to Clause 5.3 (authority). Also consider 7.1 (resources) and 5.1 (leadership).
Tip 6 – 'Assigned but unaware' means a communication failure. If interviewed staff do not know their roles, the gap is in 'communicated within the organization' (5.3). It may also involve awareness (7.3). Choose the clause that best matches the evidence.
Tip 7 – Pick the most specific clause. Scenario questions often have several plausible clauses. Use this guide:
• No risk owner identified: Clause 6.1.2 c).
• Risk owner did not approve the treatment plan: Clause 6.1.3 f).
• No one assigned to report ISMS performance: Clause 5.3 b).
• Role holder lacks the skills: Clause 7.2.
• Security roles not defined as a control: Annex A 5.2 (check the Statement of Applicability).
• Conflicting duties: Annex A 5.3.
• Top management not supporting role holders: Clause 5.1.
Tip 8 – Write findings in a structured way. In essay or case-study questions, write nonconformity statements with three parts:
• Requirement: for example, 'ISO/IEC 27001:2022 Clause 5.3 requires top management to assign responsibility and authority for reporting on the performance of the ISMS to top management.'
• Nonconformity: for example, 'No responsibility for ISMS performance reporting has been assigned.'
• Evidence: for example, 'Interview with the COO on [date] and review of management review minutes for 2023 showed no ISMS performance report was presented, and no appointment record exists.'
Keep the statement factual, objective and traceable. Do not include opinions or recommend solutions.
Tip 9 – Justify the grading. State why a finding is major or minor. Consider whether the failure is systemic, whether it affects the ability of the ISMS to achieve its intended outcomes, and whether it is a single isolated instance.
Tip 10 – Consider small organizations. In a small company, the owner may be both top management and ISMS Manager. That is acceptable. The exam may test whether you wrongly raise a finding just because roles are combined. Only raise one if there is a real conflict, such as self-audit by the internal auditor, or a missing assignment.
Tip 11 – Remember external parties. Responsibilities can be held by suppliers or outsourced providers, such as a managed SOC. The organization must still define and agree those responsibilities, normally through contracts (Annex A 5.19 and 5.20). Accountability is not outsourced.
Tip 12 – Link to audit evidence sources. If asked how you would audit Clause 5.3, list three things:
• Documents: org chart, RACI, job descriptions, appointment letters.
• Interviews: top management, the ISMS Manager, risk owners, staff.
• Observation and records: management review minutes, performance reports, committee minutes.
Sampling across levels shows assignment, authority and communication.
Tip 13 – Watch for 2013 versus 2022 wording. The 2022 edition says 'communicated within the organization'. Annex A was restructured, so the old A.6.1.1 became 5.2 and the old A.6.1.2 became 5.3. Use the current numbering unless the exam specifies otherwise.
Tip 14 – Eliminate absolute distractors. Options with words like 'must be full-time', 'must be documented in a specific procedure', 'must be certified' or 'only IT is responsible' are usually incorrect. ISO 27001 allows flexibility as long as the requirement's intent is met.
6. Quick Revision Summary
• Clause 5.3: top management ensures roles relevant to information security are assigned and communicated.
• Two mandatory assignments: (a) ISMS conformity and (b) reporting ISMS performance to top management.
• Authority must match responsibility. Accountability stays with top management.
• No specific job title is mandated, and roles may be combined if conflicts are managed.
• Supporting links: 5.1, 6.1.2 c), 6.1.3 f), 7.1, 7.2, 7.3, 9.3, and Annex A 5.2, 5.3, 5.4, 6.2.
• Auditors verify through documents, interviews and records, and grade findings by systemic impact.
Final thought: In the exam and in real audits, ask three questions. Who is responsible? Do they have the authority? Do they and others know it? If any answer is unclear, you have likely found the issue the question is testing.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!