Roles, responsibilities, and authorities (GV.RR)
This family of controls is centered around integrating cybersecurity into the roles and responsibilities of your employees. From when the employee was first hired in, to on-the-job responsibilities, or when the employee decides to leave the organization, it’s embedded in everything the employee does. This will all need to be documented and approved by management as they too will have to play an active role in how the program evolves and adapts to new threats.
GV.RR-01
First and foremost, a cybersecurity charter should be written to ensure that the responsibilities of the program are understood. This charter should include not only the responsibilities of the program and department but also the roles of those who make up the program. These roles should be determined...