GV.RR-02.038

Has your organization formally documented the roles and responsibilities for cybersecurity risk management, including RACI (Responsible, Accountable, Consulted, Informed) designations?

Explanation

Accountability for cyber risk is the focus, asking whether you have formally documented cybersecurity risk management roles and responsibilities, including RACI designations. Without clear ownership and communication channels, critical security tasks may fall through the cracks, leading to unaddressed vulnerabilities and confusion during security incidents.

Acceptable evidence would include a RACI matrix or similar documentation that identifies specific individuals or roles responsible for cybersecurity activities, approval authorities (accountable parties), subject matter experts to be consulted, and stakeholders who need to be kept informed. This might be part of a broader Information Security Management System (ISMS) document, security policies, or risk management framework.

Implementation Example

Document who is responsible and accountable for cybersecurity risk management activities and how those teams and individuals are to be consulted and informed

ID: GV.RR-02.038

Context

Function
GV: GOVERN
Category
GV.RR: Roles, Responsibilities, and Authorities
Sub-Category
Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced

Related questions