isms.coach
← All controls

A.5.2 · Organizational

Information security roles and responsibilities

Why it matters

Without named owners, controls get implemented once and then quietly rot.

How a self-led small team implements it

A simple table — control area, owner, backup — is enough for a small team; you don't need a RACI matrix.

What auditors expect to see

Roles table or org chart annotation, job description excerpts.

Track A.5.2 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.

Start your ISMS

More organizational controls