Has your organization formally documented the roles and responsibilities for cybersecurity risk management, including RACI (Responsible, Accountable, Consulted, Informed) designations?
Explanation
Accountability for cyber risk is the focus, asking whether you have formally documented cybersecurity risk management roles and responsibilities, including RACI designations. Without clear ownership and communication channels, critical security tasks may fall through the cracks, leading to unaddressed vulnerabilities and confusion during security incidents.
Acceptable evidence would include a RACI matrix or similar documentation that identifies specific individuals or roles responsible for cybersecurity activities, approval authorities (accountable parties), subject matter experts to be consulted, and stakeholders who need to be kept informed. This might be part of a broader Information Security Management System (ISMS) document, security policies, or risk management framework.
Implementation Example
Document who is responsible and accountable for cybersecurity risk management activities and how those teams and individuals are to be consulted and informed
ID: GV.RR-02.038
Context
- Function
- GV: GOVERN
- Category
- GV.RR: Roles, Responsibilities, and Authorities
- Sub-Category
- Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced
Related questions
- Have organizational leaders formally documented and agreed upon their specific roles and responsibilities for cybersecurity strategy development, implementation, and assessment?
- Does leadership actively communicate expectations for a secure and ethical culture, particularly leveraging current events as teaching opportunities?
- Does your organization have a comprehensive cybersecurity risk strategy that is reviewed and updated at least annually and after significant security events?
- Does your organization conduct regular reviews to verify that individuals responsible for managing cybersecurity risk have appropriate authority and coordination mechanisms?
- Has your organization documented risk management roles and responsibilities in a formal policy?
- Are cybersecurity responsibilities and performance requirements explicitly included in job descriptions and personnel documentation?

