DOC-004 ← Document Portal

Roles and Responsibilities in the ISMS

RACI matrix and role descriptions for cybersecurity functions
Document Number
DOC-004
Version
▸ 1.0
Status
DRAFT
Issue Date
▸ DD/MM/YYYY
Owner
▸ CISO / HR Director
Approved by
▸ Board / CEO
Legal Basis
Art. 21(1) NIS2; ISO/IEC 27001:2022 cl. 5.3
Parent Document
DOC-001 section 4

1. NIS2 Requirement – Person Responsible for Cybersecurity

⚠️
NIS2 Art. 21(1) requirement: Operators of essential/important services must designate a person responsible for cybersecurity. That person must possess appropriate knowledge and competencies.
⚠ MANDATORY – data of the person responsible for cybersecurity
FieldValue
Name▸ [First Last Name]
Title▸ [e.g. CISO, Cybersecurity Manager, IT Security Lead]
Organisational unit▸ [e.g. IT Department / Security Division]
Business telephone▸ [+XX XXX XXX XXX]
Business e-mail▸ [[email protected]]
Deputy (if applicable)▸ [First Last Name]
Date of designation▸ DD/MM/YYYY
Notified to competent authority▸ [YES / NO – date of notification]

2. Security Role Structure in the Organisation

2.1 Board / Senior Management

▸ Organisation completes – Board composition responsible for cybersecurity
NameTitleCybersecurity responsibilities
▸ CEO / PresidentOverall responsibility, policy approval, budget
▸ [Deputy / other]

2.2 CISO / Person Responsible for Cybersecurity

Responsibilities:

  • Design, implementation and maintenance of the ISMS,
  • Coordination of risk assessments (DOC-002/003),
  • Oversight of incident detection and handling (DOC-005/006/007),
  • Reporting security status to the Board at least ▸ [quarterly]min. annually,
  • Contact with national CSIRT and competent authorities,
  • Organisation and oversight of training (DOC-017),
  • Participation in BCP reviews and continuity tests.

Required competencies: ▸ [e.g. CISSP / CISM / CISA / min. X years cybersecurity experience]

2.3 System Administrator / Security Administrator

▸ Organisation completes – administrator list
NameSystem / ScopePermission levelContact
▸ [AD / servers / network / OT]▸ Domain Administrator

2.4 System Owners

A business owner is designated for each key information system. Full list in DOC-020 Asset Register.

System owner responsibilities:

  • Information classification for data processed in the system (DOC-010),
  • Approval of system access,
  • Defining RTO/RPO requirements (DOC-011),
  • Acceptance of residual risks for the system (DOC-003).

2.5 End Users

All employees, contractors and third parties with access to the organisation's systems. Obligations defined in DOC-001 section 4.5.

2.6 Incident Response Team (Internal CERT)

▸ Organisation completes – IR team composition
IR RoleNameTitleContact (24/7)
IR Coordinator (Incident Commander)▸ CISO / IT Manager
Security Analyst
Systems Administrator
Communications / Press Officer
Legal Counsel / DPO

3. RACI Matrix – Cybersecurity Functions

RACI key: R Responsible – performs the task  |  A Accountable – owns the outcome (one per task)  |  C Consulted – consulted  |  I Informed – kept informed
▸ Complete names/titles in column headers

Column headers contain roles – complete them with names or position abbreviations used in the organisation.

Function / Task Board
▸ [name]
CISO
▸ [name]
IT Admin
▸ [name]
System
Owner
HR
▸ [name]
End
User
Auditor
▸ [name]
Ext.
Supplier
ISMS MANAGEMENT
Approval of Security Policy (DOC-001)ARCIIIC
ISMS review (min. once a year)ARCCIIR
Security reporting to BoardARCIC
Ensuring security budgetARII
RISK MANAGEMENT (DOC-002, DOC-003)
Risk identification and assessmentCARRCC
Acceptance of high and critical risksARIC
Updating Risk RegisterIARCC
Implementing Risk Treatment PlansIARRCIR
INCIDENT MANAGEMENT (DOC-005, 006, 007)
Reporting a suspicious eventIARRR
Incident classification and assessmentIARC
CSIRT notification (24h/72h)IAR
Board notification of significant incidentARII
Incident response and containmentIARCR
Documentation and post-incident reportIARIC
ACCESS CONTROL (DOC-008)
Granting access permissionsARCR
Access review (min. once a year)IARRCC
MFA implementationIARC
Privileged access management (PAM)IARCC
BUSINESS CONTINUITY (DOC-011, 012)
Maintaining and updating BCPCARRC
BCP/DRP tests (min. once a year)IARRC
Data backup and recovery testsIARC
TRAINING AND AWARENESS (DOC-017)
Developing training programmeIACR
Mandatory Board training (min. once/year)RAR
Employee training (min. once/year)IACIRR
AUDIT AND COMPLIANCE (DOC-021)
Planning and conducting internal auditsIACCR
Reporting audit results to BoardARIR
Implementing audit recommendationsIARRRC

4. Emergency and External Contacts

⚠ Critical – 24/7 contacts required by NIS2
EntityContactPurpose
National CSIRT (competent authority) ▸ [contact details per national NIS2 implementation] Cybersecurity incident reporting
Sector CSIRT (if applicable) ▸ [sector-specific CSIRT contact] Sector incident reporting
DPA (Personal Data Breach) ▸ [DPA contact details] GDPR Art. 33 notification (72h)
Law Enforcement / Cybercrime Unit ▸ [contact details] Report cybercrime
Cyber Insurer ▸ [insurer details, policy number] Report cyber incident
External CERT / IR ▸ [IR provider, contact] Support for major incidents
Internal alarm line ▸ [internal extension / email] Employee reporting

5. Change History

VersionDateAuthorDescriptionApproved by
▸ 1.0 ▸ DD/MM/YYYY ▸ Initial release ▸ Board
DOC-004 Roles and Responsibilities | v1.0 | NIS2/ISMS