Skip to main content
Category: Governance and Roles

Roles and Authorities

Also known as: Roles and Responsibilities, Role-Based Access Control (related concept)
Simply put

Roles and authorities describe who is allowed to do what within an organization or system. A role groups together a set of responsibilities and the level of permission needed to carry them out, while an authority is the specific right or power granted to act. Together they help ensure that people and systems only take actions they are permitted to perform.

Formal definition

In access management, a role is a named collection of permissions typically assigned to users to govern access control, while an authority is a granted permission or right to perform a specific action; in some frameworks a role is treated as a category or grouping of authorities. At the organizational level, authority denotes the level of decision-making or approval power associated with a given responsibility, and roles map responsibilities to accountable individuals or entities. The precise implementation, such as whether roles are hierarchical or how authorities are enumerated, varies by system and governance model, and the terms are used with different technical meanings across access-control frameworks and organizational role descriptions.

Why it matters

Roles and authorities sit at the center of how organizations control who can take which actions, making them foundational to both governance and access management. When roles and authorities are clearly defined, organizations can demonstrate that responsibilities are assigned to accountable individuals and that permissions align with those responsibilities. When they are poorly defined or inconsistently applied, users and systems may accumulate access beyond what their duties require, weakening the organization's ability to enforce separation of duties and least privilege.

In a SOC 2 examination, controls addressing logical and physical access are evaluated under the Security category (the Common Criteria), and clearly articulated roles and authorities typically support the design and operating effectiveness of those controls. In an ISO/IEC 27001 context, the assignment of information security roles and responsibilities is addressed within the ISMS requirements and is commonly reflected in Annex A reference controls selected through the Statement of Applicability. In most engagements, auditors and certification bodies look for evidence that authority levels are documented and that access rights map to defined roles, though the specific expectations depend on scope and applicable criteria.

Because the terms carry different technical meanings across access-control frameworks and organizational role descriptions, ambiguity itself can become a source of risk. A role in a technical system such as a permission grouping may not correspond neatly to an organizational authority level tied to decision-making or approval power, and treating the two interchangeably can lead to misconfigured access or unclear accountability.

Who it's relevant to

Compliance and GRC managers
They rely on clearly defined roles and authorities to demonstrate that responsibilities are assigned to accountable individuals and that access aligns with duties. This supports evidence for access-related controls in both SOC 2 examinations and ISO/IEC 27001 assessments, though the specific expectations depend on scope and applicable criteria.
Security engineers and system administrators
They implement roles as collections of permissions and configure authorities as specific rights to perform actions. They must account for framework-specific behavior, such as role hierarchies where some roles include others, and ensure technical role definitions align with the organizational authority levels they are meant to enforce.
Auditors and assessors
They evaluate whether documented roles and authorities are designed appropriately and, in a SOC 2 Type II or an ISO 27001 assessment, whether they operate as intended over the relevant period or within the defined ISMS scope. They look for consistency between assigned responsibilities, granted authority levels, and actual access rights.
Organizational and business leaders
They define the decision-making and approval powers attached to responsibilities, distinguishing among the levels of authority that a given role may carry. Clear authority definitions help establish accountability and reduce ambiguity between organizational roles and their technical access counterparts.

Inside Roles and Authorities

Top Management Responsibility
ISO/IEC 27001 clause 5.3 requires top management to ensure that responsibilities and authorities for roles relevant to information security are assigned and communicated within the organization. This is one of the ISMS requirements found in clauses 4 through 10.
Assignment of Responsibilities
The requirement typically involves designating who is responsible for ensuring the ISMS conforms to the standard and who reports on ISMS performance to top management, though the specific structure and titles are left to the organization to define based on its context.
Communication of Authorities
Beyond assigning roles, the requirement calls for these responsibilities and authorities to be communicated so that relevant personnel understand their obligations. The method of communication is not prescribed and varies by organization.
Relationship to Other Clauses
Roles and authorities under clause 5.3 support related ISMS requirements such as leadership and commitment (clause 5.1), competence (clause 7.2), and awareness (clause 7.3), forming part of the broader management system rather than standing alone.
SOC 2 Treatment via Trust Services Criteria
In a SOC 2 examination, comparable concepts are addressed within the Security category (Common Criteria), which includes criteria relating to organizational structure, assignment of authority and responsibility, and accountability. These are evaluated by the CPA firm rather than certified, and should not be conflated with ISO 27001 Annex A controls.

Common questions

Answers to the questions practitioners most commonly ask about Roles and Authorities.

Is a SOC 2 report the same thing as an ISO 27001 certification when it comes to defining roles and authorities?
No. A SOC 2 report is an attestation examination performed by a licensed CPA firm under the AICPA SSAE 18 standard, resulting in a report rather than a certificate. ISO/IEC 27001 is a certification issued by an accredited certification body against a management system standard. While both frameworks address how roles and authorities are assigned, they do so through different mechanisms: SOC 2 evaluates controls against the Trust Services Criteria, whereas ISO 27001 addresses roles primarily through its ISMS requirements in clauses 4 through 10. Meeting the expectations of one framework does not automatically satisfy the other, since the mapping between them is partial.
Does assigning roles and authorities under ISO 27001 mean I have satisfied the SOC 2 requirements in this area, and vice versa?
Not automatically. Although roles and authorities requirements in the two frameworks can be mapped to one another, the mapping is partial. ISO 27001 addresses organizational roles, responsibilities, and authorities within its ISMS requirements, while SOC 2 evaluates related controls against the Trust Services Criteria, of which Security (the Common Criteria) is the only required category. Satisfying one framework's expectations for role definition does not on its own demonstrate conformity with the other. Each engagement is evaluated on its own scope, criteria, and the judgment of the auditor or certification body.
How should top management demonstrate that roles and authorities have been assigned in an ISMS?
Under ISO 27001, the requirement to assign and communicate roles, responsibilities, and authorities sits within the ISMS requirements in clauses 4 through 10, which reflect top management's leadership obligations. In most engagements, organizations demonstrate this through documented assignments such as role descriptions, organizational charts, and communicated responsibilities, along with evidence that relevant personnel are aware of their duties. The specific form of evidence expected can vary depending on the certification body and the defined scope of the ISMS.
What kind of evidence do auditors typically look for regarding roles and authorities in a SOC 2 examination?
In most SOC 2 engagements, evidence relating to roles and authorities may include documented responsibilities, organizational structures, and records showing that authority for security-related activities has been assigned and communicated. Because a Type I assessment addresses the suitability of design of controls at a point in time while a Type II assessment addresses both design and operating effectiveness over a defined review period, the nature of the evidence differs. For a Type II, auditors typically seek evidence that the assignment of roles operated as intended throughout the period. The exact evidence expected depends on scope and the judgment of the CPA firm performing the examination.
How do you handle roles and authorities when responsibilities are shared with a third party or cloud provider?
Where responsibilities are shared, organizations typically document which roles and authorities they retain and which are handled by the provider, often through a defined shared-responsibility arrangement. In ISO 27001, the boundaries of such arrangements are reflected in the defined scope of the ISMS, and the certificate covers only that scope. In SOC 2, the report attests only to the controls and period covered, so responsibilities outside the assessed boundary fall outside its coverage. Depending on scope, some organizations reference a provider's own SOC 2 report or ISO 27001 certificate as part of their oversight, but this does not transfer the organization's own accountability for defining its internal roles.
How often should roles and authorities be reviewed and updated?
Neither framework prescribes a single universal review frequency; the appropriate cadence depends on scope, organizational change, and risk. In most engagements, organizations review role assignments periodically and when significant changes occur, such as reorganizations or changes in personnel, so that assigned authorities remain current. For ISO 27001, keeping roles aligned with the ISMS supports the requirements in clauses 4 through 10. For SOC 2, a Type II examination typically expects that role assignments were maintained appropriately across the review period. The specific expectations vary with the auditor, certification body, and applicable criteria.

Common misconceptions

ISO 27001 requires appointing a dedicated Chief Information Security Officer or a named 'Information Security Manager' role.
Clause 5.3 requires that responsibilities and authorities be assigned and communicated, but it does not mandate any specific job title or a single dedicated position. Organizations may distribute these responsibilities across existing roles depending on their size, context, and scope.
Satisfying ISO 27001's roles and authorities requirement automatically meets the equivalent SOC 2 expectations.
Mapping between the frameworks is possible but partial. ISO 27001 clause 5.3 is a certifiable ISMS requirement, whereas SOC 2 evaluates organizational authority and accountability through the Trust Services Criteria in an attestation examination. Meeting one does not automatically satisfy the other, and the assessment mechanisms differ.
Documenting roles once establishes permanent compliance for this area.
Roles and authorities are expected to remain current and communicated. In most engagements, an auditor or certification body will look for evidence that assignments reflect the organization as it currently operates and are maintained over time; the specifics depend on scope, the certification body, and applicable criteria.

Best practices

Document the assignment of information security responsibilities and authorities in a form your organization can maintain, ensuring it aligns with clause 5.3 of ISO/IEC 27001 without assuming any particular job title is required.
Communicate assigned responsibilities to the relevant personnel and retain evidence of that communication, since certification bodies and CPA firms typically look for demonstrable awareness rather than documentation alone.
Ensure top management remains visibly involved in assigning and endorsing these roles, reflecting the leadership emphasis in clause 5.3 and its relationship to broader leadership requirements.
Review role and authority assignments periodically and after organizational changes so that documented responsibilities continue to reflect how the organization actually operates.
When pursuing both frameworks, map ISO 27001 roles and authorities to the relevant SOC 2 Trust Services Criteria deliberately, recognizing the mapping is partial and that each framework is assessed differently.
Scope role documentation to the defined boundaries of your ISMS or SOC 2 examination, and avoid overstating that assigned roles guarantee outcomes beyond the controls and period or scope covered.