Roles and Responsibilities in the ISMS
RACI matrix and role descriptions for cybersecurity functions
1. NIS2 Requirement – Person Responsible for Cybersecurity
⚠️
NIS2 Art. 21(1) requirement: Operators of essential/important services must designate a person responsible for cybersecurity. That person must possess appropriate knowledge and competencies.
⚠ MANDATORY – data of the person responsible for cybersecurity
| Field | Value |
|---|---|
| Name | ▸ [First Last Name] |
| Title | ▸ [e.g. CISO, Cybersecurity Manager, IT Security Lead] |
| Organisational unit | ▸ [e.g. IT Department / Security Division] |
| Business telephone | ▸ [+XX XXX XXX XXX] |
| Business e-mail | ▸ [[email protected]] |
| Deputy (if applicable) | ▸ [First Last Name] |
| Date of designation | ▸ DD/MM/YYYY |
| Notified to competent authority | ▸ [YES / NO – date of notification] |
2. Security Role Structure in the Organisation
2.1 Board / Senior Management
▸ Organisation completes – Board composition responsible for cybersecurity
| Name | Title | Cybersecurity responsibilities |
|---|---|---|
| ▸ | ▸ CEO / President | Overall responsibility, policy approval, budget |
| ▸ | ▸ [Deputy / other] | ▸ |
2.2 CISO / Person Responsible for Cybersecurity
Responsibilities:
- Design, implementation and maintenance of the ISMS,
- Coordination of risk assessments (DOC-002/003),
- Oversight of incident detection and handling (DOC-005/006/007),
- Reporting security status to the Board at least ▸ [quarterly]min. annually,
- Contact with national CSIRT and competent authorities,
- Organisation and oversight of training (DOC-017),
- Participation in BCP reviews and continuity tests.
Required competencies: ▸ [e.g. CISSP / CISM / CISA / min. X years cybersecurity experience]
2.3 System Administrator / Security Administrator
▸ Organisation completes – administrator list
| Name | System / Scope | Permission level | Contact |
|---|---|---|---|
| ▸ | ▸ [AD / servers / network / OT] | ▸ Domain Administrator | ▸ |
| ▸ | ▸ | ▸ | ▸ |
2.4 System Owners
A business owner is designated for each key information system. Full list in DOC-020 Asset Register.
System owner responsibilities:
- Information classification for data processed in the system (DOC-010),
- Approval of system access,
- Defining RTO/RPO requirements (DOC-011),
- Acceptance of residual risks for the system (DOC-003).
2.5 End Users
All employees, contractors and third parties with access to the organisation's systems. Obligations defined in DOC-001 section 4.5.
2.6 Incident Response Team (Internal CERT)
▸ Organisation completes – IR team composition
| IR Role | Name | Title | Contact (24/7) |
|---|---|---|---|
| IR Coordinator (Incident Commander) | ▸ | ▸ CISO / IT Manager | ▸ |
| Security Analyst | ▸ | ▸ | ▸ |
| Systems Administrator | ▸ | ▸ | ▸ |
| Communications / Press Officer | ▸ | ▸ | ▸ |
| Legal Counsel / DPO | ▸ | ▸ | ▸ |
3. RACI Matrix – Cybersecurity Functions
RACI key:
R Responsible – performs the task |
A Accountable – owns the outcome (one per task) |
C Consulted – consulted |
I Informed – kept informed
▸ Complete names/titles in column headers
Column headers contain roles – complete them with names or position abbreviations used in the organisation.
| Function / Task | Board ▸ [name] |
CISO ▸ [name] |
IT Admin ▸ [name] |
System Owner |
HR ▸ [name] |
End User |
Auditor ▸ [name] |
Ext. Supplier |
|---|---|---|---|---|---|---|---|---|
| ISMS MANAGEMENT | ||||||||
| Approval of Security Policy (DOC-001) | A | R | C | I | I | I | C | |
| ISMS review (min. once a year) | A | R | C | C | I | I | R | |
| Security reporting to Board | A | R | C | I | C | |||
| Ensuring security budget | A | R | I | I | ||||
| RISK MANAGEMENT (DOC-002, DOC-003) | ||||||||
| Risk identification and assessment | C | A | R | R | C | C | ||
| Acceptance of high and critical risks | A | R | I | C | ||||
| Updating Risk Register | I | A | R | C | C | |||
| Implementing Risk Treatment Plans | I | A | R | R | C | I | R | |
| INCIDENT MANAGEMENT (DOC-005, 006, 007) | ||||||||
| Reporting a suspicious event | I | A | R | R | R | |||
| Incident classification and assessment | I | A | R | C | ||||
| CSIRT notification (24h/72h) | I | A | R | |||||
| Board notification of significant incident | A | R | I | I | ||||
| Incident response and containment | I | A | R | C | R | |||
| Documentation and post-incident report | I | A | R | I | C | |||
| ACCESS CONTROL (DOC-008) | ||||||||
| Granting access permissions | A | R | C | R | ||||
| Access review (min. once a year) | I | A | R | R | C | C | ||
| MFA implementation | I | A | R | C | ||||
| Privileged access management (PAM) | I | A | R | C | C | |||
| BUSINESS CONTINUITY (DOC-011, 012) | ||||||||
| Maintaining and updating BCP | C | A | R | R | C | |||
| BCP/DRP tests (min. once a year) | I | A | R | R | C | |||
| Data backup and recovery tests | I | A | R | C | ||||
| TRAINING AND AWARENESS (DOC-017) | ||||||||
| Developing training programme | I | A | C | R | ||||
| Mandatory Board training (min. once/year) | R | A | R | |||||
| Employee training (min. once/year) | I | A | C | I | R | R | ||
| AUDIT AND COMPLIANCE (DOC-021) | ||||||||
| Planning and conducting internal audits | I | A | C | C | R | |||
| Reporting audit results to Board | A | R | I | R | ||||
| Implementing audit recommendations | I | A | R | R | R | C | ||
4. Emergency and External Contacts
⚠ Critical – 24/7 contacts required by NIS2
| Entity | Contact | Purpose |
|---|---|---|
| National CSIRT (competent authority) | ▸ [contact details per national NIS2 implementation] | Cybersecurity incident reporting |
| Sector CSIRT (if applicable) | ▸ [sector-specific CSIRT contact] | Sector incident reporting |
| DPA (Personal Data Breach) | ▸ [DPA contact details] | GDPR Art. 33 notification (72h) |
| Law Enforcement / Cybercrime Unit | ▸ [contact details] | Report cybercrime |
| Cyber Insurer | ▸ [insurer details, policy number] | Report cyber incident |
| External CERT / IR | ▸ [IR provider, contact] | Support for major incidents |
| Internal alarm line | ▸ [internal extension / email] | Employee reporting |
5. Change History
| Version | Date | Author | Description | Approved by |
|---|---|---|---|---|
| ▸ 1.0 | ▸ DD/MM/YYYY | ▸ | ▸ Initial release | ▸ Board |
DOC-004 Roles and Responsibilities | v1.0 | NIS2/ISMS