A.5.4 Organizational
Management responsibilities
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (18)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- AT-2mostlyaligns with — Both controls require management to ensure personnel receive ongoing security awareness training tailored to their roles and responsibilities.
- AT-3mostlyaligns with — Both controls require management to ensure personnel maintain role-specific security skills and qualifications through continuing professional education.
- PS-6mostlyaligns with — Both controls require management to ensure personnel acknowledge and agree to security policies and rules of behavior as a condition of employment or access.
- PS-9mostlyaligns with — Both controls require management to formally define and communicate security responsibilities for each role so personnel understand their obligations before accessing assets.
- AT-2partialcovers — A.5.4's management-focused responsibility to ensure personnel awareness addresses only a slice of AT-2's broader, organization-wide literacy training program (initial/ongoing, change-triggered, techniques, content for all users including managers).
- AT-3partialcovers — A.5.4 addresses management understanding their own role and ensuring general personnel awareness of responsibilities; this covers only a narrow slice of AT-3's specific requirements for role-based security/privacy training content, frequency, and updating.
- PM-2partialaligns with — Both controls assign senior management explicit accountability for demonstrating visible support of the information security program and its policies.
- PS-8partialaligns with — Both controls require management to enforce compliance with security policies and to apply sanctions when personnel fail to meet their security responsibilities.
- PM-2covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PS-6governs — A.5.4's governance mandate that management ensure personnel fulfil their information security responsibilities directly reaches the access-agreement domain (a core personnel responsibility), even though it does not name the specific control.
- PS-8governs — A.5.4's mandate that management ensure personnel fulfil their information security responsibilities directly places sanctions (as a key enforcement mechanism for non-compliance) inside the governance domain it owns, without naming the specific NIST control.
- PS-9governs — A.5.4's explicit mandate that management ensure personnel understand and fulfil their information security responsibilities directly places the incorporation of those same security roles/responsibilities into position descriptions inside its governance domain
Aligned NIST CSF 2.0 outcomes (19)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- GV.RR-01mostlycovers — The ISO control places explicit accountability on management to visibly support policy and ensure personnel understand and discharge their security responsibilities, which directly fulfills the CSF outcome that leadership must own cybersecurity risk and cultivate a risk-aware culture.
- GV.RR-02mostlycovers — By requiring management to define, communicate, and enforce role-specific security expectations and obligations before access is granted, the ISO control satisfies the CSF requirement to establish, communicate, and maintain cybersecurity roles and responsibilities.
- GV.RR-03mostlyaligns with — The ISO control mandates that management allocate adequate resources and project time for security processes, which aligns with the CSF outcome that sufficient resources must be provided to support the cybersecurity risk strategy and assigned responsibilities.
- PR.AT-01mostlyaligns with — The ISO control requires management to ensure personnel receive role-relevant security awareness and ongoing professional education, which matches the CSF outcome that staff must possess the knowledge and skills needed to perform their security tasks.
- GV.PO-02partialaligns with — By requiring management to mandate and enforce compliance with the information security policy and topic-specific policies, the ISO control supports the CSF outcome that policies must be communicated, enforced, and kept current.
- GV.RR-04partialaligns with — The ISO control’s emphasis on briefing personnel on security expectations and maintaining appropriate skills through employment terms aligns with the CSF outcome that cybersecurity considerations must be embedded in human-resources practices.
- GV.RR-04partialcovers — A.5.4 addresses management ensuring personnel awareness of security responsibilities, which is one slice of HR practices but leaves the bulk of GV.RR-04 (hiring, onboarding, performance, offboarding, etc.) uncovered.
- PR.AT-01partialcovers — A.5.4's management actions to ensure personnel awareness address only a slice of PR.AT-01's broader requirement for providing specific awareness/training content and skills development
- GV.PO-02covers — Assessed as NOT holding by the authoring instrument at v1.19-2026-08-23. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- GV.RR-03governs — A.5.4's mandate that management understand and act on their security roles directly places the allocation of adequate resources (commensurate with defined roles/responsibilities) inside the governance domain it names
- GV.RR-03implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Related weaknesses / CWE (3)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-269nonemitigates — By ensuring personnel receive role-specific guidelines and ongoing training, the control limits the assignment of excessive or inappropriate privileges that could arise from unclear expectations or skill gaps.
- CWE-284prevents — Requiring managers to brief personnel on their security roles and mandate policy compliance before granting access reduces the chance that staff will be given privileges without understanding or accepting the rules that govern those privileges.
- CWE-732prevents — Mandating that staff understand and follow the organization’s information-security expectations decreases the likelihood that critical resources will be left with overly permissive default or inherited permissions.
Mitigated MITRE ATT&CK techniques (95)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Prevented OWASP Web Top 10 (2025) risks (1)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.