GOV-03Governance and Accountability
Roles and responsibilities defined
Security, privacy and compliance responsibilities are assigned and communicated to the people who hold them.
Why it exists
People perform duties they know they hold.
What usually proves it
Role descriptions, RACI, acknowledgement records.
Smaller organizations
A one-page list of who does what, acknowledged by each person.
Mapped to
- Fully addressedSOC 2 Trust Services Criteria · CC1.4
- Fully addressedISO/IEC 27001 Annex A · A.5.3
- Fully addressedNIST Cybersecurity Framework · GV.RR-02
- Fully addressedPCI DSS · 12.4
- Fully addressedHIPAA Security Rule · 164.308(a)(3)
- Partially addressedGDPR · Art. 32 — Implied through appropriate measures rather than stated.
- Partially addressedEU AI Act · Art. 26(2) — Human oversight must be assigned to competent persons.
- Fully addressedNIST AI Risk Management Framework · GOVERN 2.2