ASR-01Assurance and Evidence

Controls have owners

Every control has one accountable owner and named performers for its tasks.

Why it exists

Shared ownership is the reliable route to nothing happening.

What usually proves it

Control ownership matrix, attestations.

Smaller organizations

One person, twelve controls, written down.

Mapped to

  • Fully addressedSOC 2 Trust Services Criteria · CC1.3
  • Fully addressedISO/IEC 27001 Annex A · A.5.2
  • Fully addressedNIST Cybersecurity Framework · GV.RR-02
  • Fully addressedPCI DSS · 12.4.2
  • Partially addressedHIPAA Security Rule · 164.308(a)(2) — Security official responsibility.
  • Deliberately absentGDPR — No control ownership concept.
  • Deliberately absentEU AI Act — Not addressed.
  • Fully addressedNIST AI Risk Management Framework · GOVERN 2.1