2.1.3. Organizational Structures, Roles, and Responsibilities
💡 First Principle: Security decisions only stick when the org chart makes them someone's job, in writing, before the decision is needed — undefined ownership turns every escalation into an argument instead of a decision.
A ship crossing into a storm with no clear chain of command is dangerous not because the crew lacks skill, but because everyone assumes someone else is steering when a fast call is needed. Organizations without clearly assigned security roles behave identically during an incident: multiple people believe they have authority, several believe none of it is their job, and the delay caused by that confusion often does more damage than the original event.
A well-governed organization typically structures accountability using a three lines of defense model: the first line (operational management and staff) owns and manages risk directly in day-to-day work; the second line (risk management and compliance functions, including information security) sets policy, monitors, and advises; the third line (internal audit) independently verifies that the first two lines are actually functioning as designed. Reporting-line choice for the CISO also matters: a report to the CIO can create a structural conflict of interest (the CIO is incentivized toward uptime and delivery speed, sometimes at odds with risk-averse security recommendations), while a report to a chief risk officer or directly to the board preserves independence.
Formally, organizational structures and roles assign accountability (ultimate ownership of an outcome — held by exactly one role) and responsibility (execution of the work — which can be shared across multiple roles) for information security across the enterprise. This accountable/responsible distinction, borrowed from RACI modeling, is a recurring exam theme: only one role can be accountable for a given outcome, even when many roles are responsible for tasks that contribute to it.
⚠️ Exam Trap: A classic trap tests segregation of duties by describing the same team both designing a control and independently attesting that the control works. The correct answer recognizes this as a governance violation — the group responsible for building a control should not also be the sole authority certifying its effectiveness; that is internal audit's independent role.
Reflection Question: If the same team designs a control and signs off that the control is operating effectively, what governance principle is violated, and what specific risk does that create?