A.5.2 Organizational
Information security roles and responsibilities
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (21)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PS-9mostlyaligns with — Both controls require that security-related duties be explicitly assigned to positions and documented so accountability is clear.
- AC-6partialaligns with — Both stress that individuals should be granted only the authority needed to perform their assigned security duties.
- AT-3partialaligns with — Both require that personnel assigned security responsibilities receive role-specific training and ongoing competence development.
- CA-6partialaligns with — Both require that residual-risk acceptance decisions be made by formally designated authorities.
- PM-2partialaligns with — Both emphasize designating senior leadership with overall responsibility for the information-security program and its governance.
- PM-2partialcovers — A.5.2's focus on defining an understood structure for security roles/responsibilities addresses only a slice of PM-2's requirement to appoint a specific senior officer with mission/resources to lead the full program
- AC-6governs — A.5.2's mandate for a defined structure of security roles/responsibilities directly includes assigning and enforcing least-privilege rules as part of the operational implementation of information security, making the governance link inferential but present within the domain.
- CA-6governs — A.5.2's mandate to establish a defined structure for security roles and responsibilities directly supplies the governance domain that requires a senior authorizing official (and the authorization process itself) as described in CA-6
- PS-9governs — A.5.2's mandate to establish a defined structure for security roles and responsibilities directly places the organizational position-description requirement of PS-9 inside its governance domain
Aligned NIST CSF 2.0 outcomes (16)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- GV.RR-02fullcovers — The ISO control directly establishes, documents, and communicates cybersecurity roles and responsibilities across the organization, which is the core outcome of this CSF subcategory.
- GV.RR-01mostlyaligns with — By requiring leadership accountability for security responsibilities and ensuring delegated tasks are verified, the control supports the CSF outcome of leadership ownership and a risk-aware culture.
- GV.SC-02mostlycovers — A.5.2's broad mandate for defined/approved/understood security roles and responsibilities fully accounts for establishing and coordinating cybersecurity roles for external parties (suppliers/customers/partners) as one slice of the overall structure, but leaves a residual of the target uncovered around explicit external communication/coordination obligations that sit outside A.5.2's internal organizational focus.
- GV.RR-03partialaligns with — The control's emphasis on competence, ongoing support, and defined authorization levels helps ensure resources are allocated appropriately to fulfill assigned security roles.
- GV.RR-04partialaligns with — Requiring individuals to be competent and kept current in their security roles aligns with incorporating cybersecurity responsibilities into human resources practices.
- GV.RR-04partialcovers — A.5.2's focus on defining security roles and responsibilities addresses only a slice of GV.RR-04's broader requirement to embed cybersecurity into all HR practices (hiring, onboarding, training, performance, offboarding, etc.)
- GV.SC-02partialaligns with — The control's requirement to define and communicate responsibilities for all personnel using organizational assets extends to supplier and partner coordination when third parties are involved.
- GV.RR-01governs — A.5.2 mandates the governance structure (roles/responsibilities) that directly owns accountability for cybersecurity risk and risk-aware culture, which is the exact subject of GV.RR-01; this is a domain-level governance mandate rather than an explicit citation of the outcome.
- GV.RR-01implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Related OWASP ASVS 5.0 requirements (4)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Related weaknesses / CWE (5)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-269prevents — Defining and communicating authorization levels for each role limits the assignment of excessive or unnecessary privileges.
- CWE-284prevents — Explicitly assigning and documenting who owns each security responsibility reduces the chance that access decisions are left undefined or inconsistently enforced.
- CWE-708prevents — Role definitions can require ownership accountability, but the control itself does not address technical assignment errors.
- CWE-732prevents — Documented responsibility for protecting assets encourages correct permission settings rather than leaving them at insecure defaults.
Mitigated MITRE ATT&CK techniques (204)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Prevented OWASP Web Top 10 (2025) risks (1)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.