A.5.4 Organizational
Management responsibilities
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (11)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- AT-2mostlyaligns with — Both controls require management to ensure personnel receive ongoing security awareness training tailored to their roles and responsibilities.
- AT-3mostlyaligns with — Both controls require management to ensure personnel maintain role-specific security skills and qualifications through continuing professional education.
- PS-6mostlyaligns with — Both controls require management to ensure personnel acknowledge and agree to security policies and rules of behavior as a condition of employment or access.
- PS-9mostlyaligns with — Both controls require management to formally define and communicate security responsibilities for each role so personnel understand their obligations before accessing assets.
- PM-2partialaligns with — Both controls assign senior management explicit accountability for demonstrating visible support of the information security program and its policies.
- PS-8partialaligns with — Both controls require management to enforce compliance with security policies and to apply sanctions when personnel fail to meet their security responsibilities.
Aligned NIST CSF 2.0 outcomes (13)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- GV.RR-01mostlycovers — The ISO control places explicit accountability on management to visibly support policy and ensure personnel understand and discharge their security responsibilities, which directly fulfills the CSF outcome that leadership must own cybersecurity risk and cultivate a risk-aware culture.
- GV.RR-02mostlycovers — By requiring management to define, communicate, and enforce role-specific security expectations and obligations before access is granted, the ISO control satisfies the CSF requirement to establish, communicate, and maintain cybersecurity roles and responsibilities.
- GV.RR-03mostlyaligns with — The ISO control mandates that management allocate adequate resources and project time for security processes, which aligns with the CSF outcome that sufficient resources must be provided to support the cybersecurity risk strategy and assigned responsibilities.
- PR.AT-01mostlyaligns with — The ISO control requires management to ensure personnel receive role-relevant security awareness and ongoing professional education, which matches the CSF outcome that staff must possess the knowledge and skills needed to perform their security tasks.
- GV.PO-02partialaligns with — By requiring management to mandate and enforce compliance with the information security policy and topic-specific policies, the ISO control supports the CSF outcome that policies must be communicated, enforced, and kept current.
- GV.RR-04partialaligns with — The ISO control’s emphasis on briefing personnel on security expectations and maintaining appropriate skills through employment terms aligns with the CSF outcome that cybersecurity considerations must be embedded in human-resources practices.
Related weaknesses / CWE (5)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-284partialprevents — Requiring managers to brief personnel on their security roles and mandate policy compliance before granting access reduces the chance that staff will be given privileges without understanding or accepting the rules that govern those privileges.
- CWE-732partialprevents — Mandating that staff understand and follow the organization’s information-security expectations decreases the likelihood that critical resources will be left with overly permissive default or inherited permissions.
- CWE-250nonenone — Requiring managers to verify that employees have the correct skills and are explicitly required to comply with policy reduces the probability that processes will run with unnecessary or elevated privileges.
- CWE-269nonemitigates — By ensuring personnel receive role-specific guidelines and ongoing training, the control limits the assignment of excessive or inappropriate privileges that could arise from unclear expectations or skill gaps.
- CWE-778nonenone — Providing a confidential reporting channel for policy violations increases the chance that security-relevant events will be surfaced and recorded rather than remaining undetected.
Mitigated MITRE ATT&CK techniques (5)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1078partialmitigates — Ensuring staff are vetted, briefed on acceptable use, and required to comply with policy before receiving credentials limits the abuse of valid accounts obtained through social engineering or policy violations.
- T1110nonemitigates — Requiring ongoing professional education and policy adherence reduces the probability that users will choose weak or reused passwords that enable brute-force or credential-stuffing attacks.
- T1204nonemitigates — Requiring managers to brief staff on security expectations and mandate policy compliance before granting access reduces the likelihood that users will execute malicious files or links delivered via phishing.
- T1552nonemitigates — By holding personnel accountable for secure handling of credentials and providing confidential reporting channels, the control decreases the chance that credentials will be left in files, scripts, or chat messages.
- T1566nonemitigates — Mandating that personnel receive role-specific security awareness and policy briefings before system access lowers the chance they will fall for spear-phishing attachments or links.
Prevented OWASP Web Top 10 (2025) risks (3)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A02partialmitigates — By requiring management to brief staff on security expectations and mandate policy compliance before granting access, the control reduces the chance that systems are deployed or configured without following security standards.
- A09partialmitigates — Establishing a confidential channel for reporting policy violations increases the likelihood that security events are surfaced and can be logged or investigated rather than remaining undetected.
- A07noneprevents — Mandating that personnel receive role-specific security briefings and ongoing training before access is granted helps ensure authentication mechanisms are understood and used correctly from the outset.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.