ASR-01Assurance and Evidence
Controls have owners
Every control has one accountable owner and named performers for its tasks.
Why it exists
Shared ownership is the reliable route to nothing happening.
What usually proves it
Control ownership matrix, attestations.
Smaller organizations
One person, twelve controls, written down.
Mapped to
- Fully addressedSOC 2 Trust Services Criteria · CC1.3
- Fully addressedISO/IEC 27001 Annex A · A.5.2
- Fully addressedNIST Cybersecurity Framework · GV.RR-02
- Fully addressedPCI DSS · 12.4.2
- Partially addressedHIPAA Security Rule · 164.308(a)(2) — Security official responsibility.
- Deliberately absentGDPR — No control ownership concept.
- Deliberately absentEU AI Act — Not addressed.
- Fully addressedNIST AI Risk Management Framework · GOVERN 2.1