What to Provide
The documented policy/procedure (or similar documentation) that define the job responsibilities for the common roles that oversee the implementation of the security and control environment.
Evidence Format
Word/PDF document
Additional Guidance
Common roles that oversee the implementation of the security and control environment include:
Chief Executive Officer (CEO)
Chief Information Security Officer (CISO)
Chief Technology Officer (CTO)
Data Privacy Officer (DPO)
Risk and Compliance Officer
Incident Response Team (IRT) Security Officer
Security Director or Manager
The evidence should demonstrate:
Individual or team names
Defined individual or team responsibilities
Associated Unified Control ID | Associated Framework Control |
CTRL-432 | LCL-7 |