Example Roles and Responsibilities Matrix
Example Roles and Responsibilities Matrix
Role Responsibilities
CEO • Provides overall direction, guidance, leadership, and support for the entire organization
• Commits to implementing an information security management system (ISMS) and
providing the necessary support
CIO • Provides overall direction, guidance, leadership, and support for the entire information
systems environment
• Assists applicable personnel in their day-to-day operations
• Reports to other members of senior management on a regular basis regarding aspects
of the information systems posture
Security Director • Develops, implements, and maintains the information security program
• Ensures the ISMS complies with ISO 27001
Network Engineers • Plan, design, implement, document, operate, maintain, and optimize the organization’s
Systems Administrators network infrastructure
• Manage the organization’s network infrastructure and collaborate with other systems
engineers to maintain and optimize the network
End Users • Adhere to the organization’s information security policies, procedures, and practices
• Report instances of noncompliance to senior authorities
• Undertake day-to-day operations while also observing and reporting any issues that
could impede the safety and security of the organization’s system components
Vendors • Adhere to the organization’s information security policies, procedures, and practices
Contractors
Third Parties
Building an ISO 27001-Compliant Cybersecurity Program: Getting Started with Marc Menninger 1 of 1