Practical Roles and Responsibilities for an ISO 27001 ISMS
A successful ISO/IEC 27001 Information Security Management System (ISMS) requires clear ownership.
ISO 27001 does not mean that one person—usually the IT or security manager—becomes responsible for everything.
Information security responsibilities should be assigned across management, security, IT, engineering, HR, procurement, employees and other relevant functions.
For startups, the same person may perform multiple roles. What matters is that responsibilities are clearly assigned and that important activities have appropriate ownership and oversight.
1. ISO 27001 Responsibility Structure
A practical startup structure can look like this:
Top Management
↓
ISMS Manager / Information Security Lead
↓
Control Owners
↓
IT / Engineering / HR / Procurement / Business Teams
↓
All Employees & Contractors
The exact job titles can vary. ISO 27001 focuses on appropriate responsibilities and authorities rather than requiring specific job titles.
2. Core ISO 27001 Roles
| Role | Primary Responsibility |
|---|---|
| Top Management | Direction, commitment, resources and ISMS oversight |
| ISMS Manager / Security Lead | Coordinate and operate the ISMS |
| Risk Owners | Own and manage specific information security risks |
| Control Owners | Ensure assigned controls are implemented and operating |
| IT / Cloud Team | Infrastructure and technical security |
| Engineering Team | Secure development and application security |
| HR | Personnel security and employee lifecycle |
| Procurement / Vendor Management | Supplier security |
| Legal / Compliance | Regulatory and contractual requirements |
| Internal Auditor | Independently evaluate the ISMS |
| All Employees | Follow security requirements and report incidents |
A startup may combine several of these responsibilities into a small number of people.
3. Top Management
Role
Top management provides leadership and accountability for the ISMS.
Responsibilities
- Approve the ISMS scope
- Approve the Information Security Policy
- Ensure information security objectives are established
- Provide appropriate resources
- Assign responsibilities and authorities
- Ensure information security requirements are integrated into business processes
- Review ISMS performance
- Participate in management review
- Support continual improvement
- Ensure significant information security risks receive appropriate attention
Example
For a 30-person SaaS startup:
CEO → Executive sponsor
The CEO does not need to manage AWS configurations or review firewall rules.
Instead, management should ensure that:
“The organization has an effective ISMS, appropriate resources are available, significant risks are addressed, and security performance is reviewed.”
4. ISMS Manager / Information Security Lead
This person coordinates the ISMS on a day-to-day basis.
Responsibilities
- Maintain the ISMS
- Coordinate risk assessments
- Maintain the risk register
- Coordinate risk treatment
- Maintain the Statement of Applicability
- Coordinate security policies
- Track control implementation
- Coordinate internal audits
- Track corrective actions
- Coordinate management reviews
- Monitor ISMS performance
- Coordinate security awareness
- Report significant issues to management
Important
The ISMS Manager does not necessarily own every security control.
For example:
| Activity | Owner |
|---|---|
| AWS IAM | Cloud/IT |
| Secure coding | Engineering |
| Employee onboarding | HR |
| Supplier assessment | Procurement |
| Risk register | ISMS Manager |
| Management review | Top Management |
The ISMS Manager coordinates the system; control owners operate their respective controls.
5. Risk Owner
Every significant information security risk should have an identifiable owner.
Responsibilities
- Understand the assigned risk
- Review risk rating
- Decide or recommend treatment
- Ensure treatment actions are completed
- Monitor residual risk
- Escalate unacceptable risk
- Participate in risk reviews
- Approve risk acceptance where authorized
Example
Risk: Unauthorized production access
Risk Owner: CTO
The CTO may delegate implementation to the cloud team, but remains accountable for the business risk.
6. Control Owner
A control owner is responsible for ensuring that a particular control is implemented and operating.
Responsibilities
- Understand the control objective
- Define how the control operates
- Ensure implementation
- Maintain relevant evidence
- Monitor control performance
- Address control failures
- Support internal audits
- Review the control periodically
Example
Control: Privileged access management
Control Owner: IT Manager / Cloud Security Lead
Evidence:
- AWS IAM configuration
- Privileged user list
- MFA configuration
- Access approvals
- Periodic access review
7. IT / Cloud Infrastructure Team
For an AWS-based startup, IT or the cloud team may own many technological controls.
Responsibilities
- Identity and access management
- Cloud security configuration
- Network security
- Endpoint security
- Backup
- Logging
- Monitoring
- Vulnerability management
- Configuration management
- Security patching
- Infrastructure changes
- Disaster recovery
- Technical incident response
Example
For AWS:
- IAM
- Security Groups
- CloudTrail
- CloudWatch
- S3 security
- RDS security
- Backup
- WAF
- Encryption
8. Engineering / Development Team
Engineering is responsible for integrating security into the software development lifecycle.
Responsibilities
- Secure software development
- Security requirements
- Code review
- Dependency management
- Vulnerability remediation
- Security testing
- Source-code access
- Branch protection
- Change management
- Production deployment controls
- Secure handling of secrets
- Remediation of application vulnerabilities
Example
Before a major application release:
Requirement → Development → Code Review → Security Testing → Approval → Production Deployment
The engineering team should be able to demonstrate evidence of this process.
9. HR / People Team
HR plays an important role in people-related security controls.
Responsibilities
- Security responsibilities during recruitment
- Background verification where applicable
- Confidentiality obligations
- Employee security awareness
- Security training
- Onboarding
- Role changes
- Offboarding
- Return of company assets
- Access termination coordination
- Employee records protection
Example
When an employee leaves:
HR termination notification
↓
IT access removal
↓
Asset recovery
↓
Account closure
↓
Evidence retained
This process should have clear ownership.
10. Procurement / Vendor Management
Organizations rely heavily on third-party services.
A startup may use:
- AWS
- GitHub
- Microsoft 365
- Google Workspace
- Slack
- HR platforms
- Payment providers
- External developers
- MSSPs
- Security consultants
Responsibilities
- Identify critical suppliers
- Perform supplier security assessment
- Review security requirements
- Include security clauses in contracts where appropriate
- Monitor critical suppliers
- Track supplier risks
- Review supplier changes
- Maintain supplier records
11. Legal / Compliance
Where applicable, Legal or Compliance should support:
- Regulatory requirements
- Contractual requirements
- Privacy requirements
- Customer security obligations
- Data protection requirements
- Retention requirements
- Legal requirements relevant to information security
For smaller startups, this responsibility may be assigned to an external legal advisor or compliance consultant.
12. Incident Response Team
Incident response does not necessarily require a dedicated department.
A startup can establish a small incident response group.
Example
Incident Response Team
- Security Lead — Incident Coordinator
- CTO — Technical escalation
- Engineering Lead — Application investigation
- IT — Infrastructure investigation
- HR — Employee-related incidents
- Legal — Regulatory/contractual assessment
- CEO — Major business decisions
Responsibilities
- Detect incidents
- Report incidents
- Assess severity
- Contain incidents
- Investigate
- Communicate
- Recover
- Document
- Perform lessons learned
- Update risks and controls where necessary
13. Internal Auditor
The internal auditor evaluates whether the ISMS is operating as intended.
Responsibilities
- Plan internal audits
- Define audit scope and criteria
- Review documented information
- Interview personnel
- Sample evidence
- Test controls
- Identify nonconformities
- Identify improvement opportunities
- Prepare audit reports
- Verify corrective actions
Independence
Where practical, the person auditing a process should not simply audit their own work.
For example:
Cloud Engineer implements IAM controls
and
Internal Auditor independently tests those controls.
For a small startup where personnel are limited, appropriate arrangements should be made to maintain objectivity.
14. All Employees and Contractors
Information security is not only a management responsibility.
Every employee and relevant contractor should:
- Follow security policies
- Protect company information
- Protect credentials
- Use systems appropriately
- Complete required security training
- Report suspected incidents
- Report lost/stolen devices
- Follow data handling requirements
- Follow access control requirements
- Protect confidential information
Example
If an employee receives a suspicious phishing email, their responsibility is not to investigate the attacker.
Their responsibility is to report it through the defined incident-reporting process.
15. Startup-Friendly RACI Matrix
A RACI matrix can make ownership clearer.
R = Responsible
Performs the activity.
A = Accountable
Ultimately owns the outcome.
C = Consulted
Provides input.
I = Informed
Needs to be kept informed.
| Activity | CEO | ISMS Lead | CTO/IT | Engineering | HR | Procurement | Internal Auditor |
|---|---|---|---|---|---|---|---|
| ISMS Scope | A | R | C | C | C | I | C |
| Security Policy | A | R | C | C | C | I | I |
| Risk Assessment | A | R | C | C | C | C | I |
| Risk Treatment | A | R | R | R | R | R | I |
| SoA | A | R | C | C | C | C | I |
| Access Management | I | C | A/R | C | C | I | I |
| Secure Development | I | C | A | R | I | I | I |
| Employee Security | I | C | C | I | A/R | I | I |
| Supplier Security | I | C | C | C | I | A/R | I |
| Incident Management | A | R | R | R | C | C | I |
| Business Continuity | A | R | R | C | C | C | I |
| Internal Audit | I | C | C | C | C | C | A/R |
| Management Review | A/R | R | C | C | C | C | I |
| Corrective Actions | A | R | R | R | R | R | C |
This matrix should be customized according to the organization’s structure.
16. Example: 25-Person SaaS Startup
A startup does not need 10 separate ISO managers.
One practical structure could be:
CEO
Top Management / ISMS Sponsor
CTO
Technology & Security Owner
Security/Compliance Manager
ISMS Manager
Engineering Lead
Secure Development Control Owner
IT Administrator
Access / Endpoint / Infrastructure Control Owner
HR Manager
People Security Owner
Operations/Procurement
Supplier Management Owner
External Auditor / Independent Internal Auditor
Internal Audit
This can be sufficient if responsibilities, authority and segregation are properly defined.
17. Example Responsibility Assignment
Risk
Unauthorized AWS production access
Risk Owner: CTO
Control Owners:
- IAM → IT/Cloud
- Application access → Engineering
- Access review → Security/Compliance
- Employee termination → HR + IT
Evidence
- IAM configuration
- MFA report
- Access approval
- Access review
- Employee termination records
- CloudTrail logs
This demonstrates why ISO 27001 roles should be connected to risks and controls, rather than existing only as an organizational chart.
18. Roles vs Responsibilities vs Evidence
A useful way to design your ISMS is:
Role → Responsibility → Activity → Evidence
Example
Role: HR Manager
Responsibility: Employee security
Activity: Employee offboarding
Evidence:
- HR termination record
- IT access-removal ticket
- Asset return record
Another example:
Role: Cloud Administrator
Responsibility: AWS access management
Activity: Quarterly privileged access review
Evidence:
- Access review report
- Approval record
- IAM configuration
19. ISO 27001 Roles & Responsibilities Template
Organizations can adapt the following template.
Role
Role Name:
[Enter role]
Person:
[Enter person]
Department:
[Enter department]
Reports To:
[Enter manager]
Responsibilities
The role is responsible for:
- [Responsibility]
- [Responsibility]
- [Responsibility]
- [Responsibility]
Authority
The role has authority to:
- [Authority]
- [Authority]
- [Authority]
ISMS Activities
- ☐ Risk management
- ☐ Control implementation
- ☐ Security monitoring
- ☐ Incident management
- ☐ Security awareness
- ☐ Internal audit
- ☐ Management review
- ☐ Corrective action
Evidence
The role is responsible for maintaining:
- [Record]
- [Report]
- [Approval]
- [System evidence]
Review
Review Frequency: [Monthly / Quarterly / Annual / As Required]
Approved By: [Name/Role]
Effective Date: [Date]
20. Minimum Roles for a Small Startup
For a very small organization, the following structure may be enough:
| ISMS Responsibility | Possible Owner |
|---|---|
| Executive accountability | CEO |
| ISMS coordination | Compliance/Security Lead |
| Technology security | CTO |
| Cloud security | CTO/Cloud Engineer |
| Application security | Engineering Lead |
| People security | HR |
| Supplier security | Operations |
| Incident response | Security Lead + CTO |
| Risk ownership | Business/Function Owners |
| Internal audit | Independent person |
| Certification audit | Independent Certification Body |
The same person can hold multiple responsibilities where appropriate, but independence and conflicts of interest should be considered, particularly for internal auditing.
21. Common Startup Mistakes
❌ “The CISO owns ISO 27001.”
The ISMS should have organization-wide ownership and management support.
❌ “The IT team is responsible for everything.”
HR, Engineering, Procurement, Management and employees all have security responsibilities.
❌ “The consultant is responsible for our ISMS.”
A consultant can support implementation, but the organization retains ownership of its ISMS, risks and decisions.
❌ “The person who implemented the control should automatically audit it.”
Internal audit should be performed with appropriate objectivity and impartiality.
❌ “We only need to define responsibilities for the audit.”
Responsibilities should operate as part of normal business operations.
22. The Golden Rule
For every important ISO 27001 activity, ask three questions:
1. Who is accountable?
Who ultimately owns the outcome?
2. Who performs the activity?
Who actually carries out the work?
3. What evidence proves it happened?
If these three questions can be answered clearly, the organization is much less likely to have responsibility gaps.
Quick Startup Summary
An effective ISO 27001 responsibility structure does not need to be complicated.
Management provides direction and resources.
ISMS/Security Lead coordinates the ISMS.
Risk Owners own information security risks.
Control Owners operate individual controls.
IT/Engineering/HR/Procurement implement security within their functions.
Employees follow security requirements and report incidents.
Internal Auditors independently evaluate the ISMS.
The objective is not to create more titles.
The objective is to ensure that every important information security responsibility has a clear owner, appropriate authority and demonstrable evidence.
