unified
UC-GOV-06 — Define security roles, responsibilities, and authorities
Establish and document organizational structures, reporting lines, and the roles, responsibilities, and authorities for information security, risk management, and internal control, with board oversight of their design. Communicate assignments to the individuals and teams concerned, keep them current through organizational and personnel change, and enforce them in practice so that ownership of each security obligation is unambiguous.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Governance, Policy & Oversight
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-GOV-06
- title
- Define security roles, responsibilities, and authorities
- statement
- Establish and document organizational structures, reporting lines, and the roles, responsibilities, and authorities for information security, risk management, and internal control, with board oversight of their design. Communicate assignments to the individuals and teams concerned, keep them current through organizational and personnel change, and enforce them in practice so that ownership of each security obligation is unambiguous.
- domain
- Governance, Policy & Oversight
- control_type
- preventive
- control_category
- administrative
- members
- framework
- iso-27001
- control_id
- A.5.2
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- GV.RR-02
- coverage
- full
- relationship
- superset_of
- framework
- soc2
- control_id
- CC1.3
- coverage
- full
- relationship
- superset_of
- framework
- coso-ic
- control_id
- P3
- coverage
- full
- relationship
- superset_of
- framework
- coso-erm
- control_id
- E2
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-GOV-06 — Define security roles, responsibilities, and authorities maps_to E2 — Establishes Operating Structures
- framework
- coso-erm
- control_id
- E2
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-06 — Define security roles, responsibilities, and authorities mitigates Core process breakdown and inability to scale
- strength
- related
- rationale
- UC-GOV-06 — Define security roles, responsibilities, and authorities mitigates Missing or insufficient security and privacy policies
- strength
- primary
- rationale
- Defining and assigning security roles, responsibilities, and authorities directly remedies undefined roles and duties.
- UC-GOV-06 — Define security roles, responsibilities, and authorities maps_to GV.RR-02 — Roles, Responsibilities, and Authorities: Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced
- framework
- nist-csf-2
- control_id
- GV.RR-02
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-06 — Define security roles, responsibilities, and authorities maps_to A.5.2 — Information security roles and responsibilities
- framework
- iso-27001
- control_id
- A.5.2
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Information Security Program Governance Review operates UC-GOV-06 — Define security roles, responsibilities, and authorities
- UC-GOV-06 — Define security roles, responsibilities, and authorities maps_to CC1.3 — Management establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities in the pursuit of objectives.
- framework
- soc2
- control_id
- CC1.3
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017 TSC
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- CSF 2.0 Profile & Maturity Assessment oversees UC-GOV-06 — Define security roles, responsibilities, and authorities
- UC-GOV-06 — Define security roles, responsibilities, and authorities maps_to P3 — Management establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities in the pursuit of objectives.
- framework
- coso-ic
- control_id
- P3
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2013
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- ISO 27001 SoA Review & Controls Assessment oversees UC-GOV-06 — Define security roles, responsibilities, and authorities
- ISO 27001 Stage 1 ISMS Documentation Review tests UC-GOV-06 — Define security roles, responsibilities, and authorities
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-GOV-06 — Define security roles, responsibilities, and authorities
- SOC 2 Trust Services Readiness tests UC-GOV-06 — Define security roles, responsibilities, and authorities