unified

UC-GOV-06 — Define security roles, responsibilities, and authorities

Establish and document organizational structures, reporting lines, and the roles, responsibilities, and authorities for information security, risk management, and internal control, with board oversight of their design. Communicate assignments to the individuals and teams concerned, keep them current through organizational and personnel change, and enforce them in practice so that ownership of each security obligation is unambiguous.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Governance, Policy & Oversight
type
preventive
category
administrative

Details

unified_id
UC-GOV-06
title
Define security roles, responsibilities, and authorities
statement
Establish and document organizational structures, reporting lines, and the roles, responsibilities, and authorities for information security, risk management, and internal control, with board oversight of their design. Communicate assignments to the individuals and teams concerned, keep them current through organizational and personnel change, and enforce them in practice so that ownership of each security obligation is unambiguous.
domain
Governance, Policy & Oversight
control_type
preventive
control_category
administrative
members
  • framework
    iso-27001
    control_id
    A.5.2
    coverage
    full
    relationship
    superset_of
  • framework
    nist-csf-2
    control_id
    GV.RR-02
    coverage
    full
    relationship
    superset_of
  • framework
    soc2
    control_id
    CC1.3
    coverage
    full
    relationship
    superset_of
  • framework
    coso-ic
    control_id
    P3
    coverage
    full
    relationship
    superset_of
  • framework
    coso-erm
    control_id
    E2
    coverage
    full
    relationship
    superset_of
guidance

    Source

    No record-specific source URL is provided.

    Connections