Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Policy Development & Approval Responsibility Matrix

Clarifies who drafts, who is consulted, who approves and who communicates each document type.

Available soon

Format
Excel
Size
68 KB
Length
12 sheets
Version
1.0
Updated

What's inside

  • Instructions
  • Responsibility Matrix
  • By Document Type
  • Role Holders
  • Role Combinations
  • Combined Roles Check
  • Lists
  • Definitions
  • Framework References

Preview

The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.

Instructions

How to use this workbook

StepWhat to do
1Read the Responsibility Matrix. Each row is one activity in a document's life, with the rule of the Policy Framework Standard it comes from. R = does the work; A = accountable, signs it off, exactly one per activity; C = consulted before it is done; I = informed after. A/R means the accountable role also does the work.
2Adjust the letters to how your organisation works, using the drop-down in each yellow cell. Keep exactly one A (or A/R) and at least one R per row: the Check column says OK only when both hold.
3Keep the four approval rows (PD-06 to PD-09) as they are unless your approved Policy Framework Standard changes who approves each tier. By Document Type reads the approving role from those rows and flags any that no longer matches.
4On Role Holders, name the post that holds each role and its deputy. A deputy may act for a role only at the same or a higher level of authority; approval authority is never delegated downwards.
5If one person holds several roles, list them on Combined Roles Check and mark each role they hold. The Result column shows whether any combination is never acceptable, or needs the safeguard on Role Combinations.
6Resolve every Never acceptable combination before approving this matrix, by moving a role to someone else or to an external reviewer. Record the safeguard you use for each Acceptable with safeguard combination.
7Review the matrix with the Policy Framework Standard, at least every 12 months, and whenever a role holder changes.
8The EXAMPLE rows on Combined Roles Check are the example organisation used across the pack (a software services company with 240 staff in two offices, an NIS2 important entity); each person's documents come from its example register. Delete them before approval.

Legend

Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.

EXAMPLERows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval.

Tailoring — small organisation: one person may hold several roles. Typically the managing director is executive management, and the IT manager is document owner, author, information security and publisher. That works with the safeguards on Role Combinations; the rule that never bends is that nobody approves a document they own or wrote (PF-03). The one thing to buy in is an independent reviewer: an external adviser or your auditor, once a year.

Tailoring — regulated entity (NIS2, DORA): the management body approves the cybersecurity risk-management measures (NIS2 Article 20(1)), so the Policy approval row (PD-06) is the management body itself, with a minute, not a delegate. DORA financial entities must set out the roles for developing, implementing and maintaining ICT security policies (RTS 2024/1774 Article 2(2)(i)): this matrix, approved, is that record. Keep the independent reviewer separate from information security and executive management.

Tailoring — IT run by a service provider: a provider may draft standards and procedures for the services it runs (Author) and be consulted on policies. Ownership and every A stay with people in your organisation; the provider never approves a document that governs its own work. Put its drafting and review duties in the service agreement.

Delegation: a deputy may act for a role while its holder is absent, at the same or a higher level of authority, and is bound by the same combination rules as the person they stand in for.

Responsibility Matrix

R = responsible (does it) · A = accountable (exactly one per activity) · C = consulted · I = informed · A/R = accountable and does it. Yellow cells are yours to adjust.

RefStageActivityRuleDocument ownerAuthorInformation securityExecutive managementConsulted functionsPublisherIndependent reviewerOutput, evidence or noteA countR countCheck
PD-01PlanIdentify the need for a new document, or for a change to one, from the coverage gap assessment or a review triggerPF-06RACCEntry in the Policy Register & Review Schedule with status Draft; for gaps, the Policy Coverage Gap Assessment11OK
PD-02PlanSet the document's tier and name its one ownerPF-01, PF-02CA/RCTier and owner recorded in the register; the hierarchy in the Security Policy Hierarchy & Document Map11OK
PD-03DraftDraft the document: for a policy, the sections in order, testable "must" statements, within the page limitPF-04, PF-05ARCDraft on the Security Policy Document Template (policies) or the house format for its tier11OK
PD-04DraftConsult the people who must follow the documentPF-07ARCCIStatus In consultation; comments and responses recorded11OK
PD-05DraftLegal, HR and data protection review, where the document affects themPF-07ARIREach function's comments resolved, or its objection recorded for the approver12OK
PD-06ApproveApprove a Policy: executive management (the management body, or its delegate for the top policy)PF-03RICAThe owner presents the final text; executive management decides and the decision is minuted. If the approver owns or wrote it: the rest of executive management, without the member who owns or wrote it11OK
PD-07ApproveApprove a Standard: Head of Information Security (the document owner is consulted)PF-03CIA/RIThe Head of Information Security approves; the document owner is consulted. If the approver owns or wrote it: executive management11OK
PD-08ApproveApprove a Procedure: Head of Information Security (the process owner is consulted)PF-03RIAInformation security approves procedures, with the process owner consulted (TIERS). Where information security owns or wrote the procedure, executive management approves instead (CONFLICT_APPROVER, PF-03). If the approver owns or wrote it: executive management11OK
PD-09ApproveApprove a Guideline: information securityPF-03CIA/RInformation security approves. If the approver owns or wrote it: executive management11OK
PD-10PublishPublish the approved version in the one place everyone can reach, and update the registerPF-03, PF-08, PF-11ARRStatus Approved; approval date and next review date in the register. Not in force until published12OK
PD-11PublishWithdraw and archive the superseded versionPF-08IAROnly the current version reachable; the old one archived with its approval record11OK
PD-12AcknowledgeRun the acknowledgement campaign: new starters within 10 working days of starting, everyone within 30 calendar days of the publication of a material change, and once a year, for every policy that applies to the personPF-09CAIRAcknowledgements recorded in the Policy Attestation & Acknowledgement Tracker. Only Policy-tier documents are acknowledged individually; a new major version is acknowledged again, a minor one is not11OK
PD-13AcknowledgeChase overdue acknowledgements through each person's line managerPF-09AIROverdue list by manager (PM-04)11OK
PD-14ReviewReview each document by its tier's maximum interval (Policy 12 months, Standard 12 months, Procedure 24 months, Guideline 24 months)PF-06A/RRCCReview recorded even when nothing changes; a changed document is approved again at its tier (PD-06 to PD-09)12OK
PD-15ReviewReview a document early when a trigger occursPF-06A/RRITriggers: a major incident, or an incident the document should have prevented; a material change to the organisation's activities, systems or suppliers; a change in law, regulation or a contract the document supports; an audit or assessment finding against the document; a significant change in the threats the document addresses12OK
PD-16RetireRetire a document that is no longer needed, and remove it from usePF-08, PF-11RAIRStatus Retired in the register; archived with its approval history. Anything that still depends on it is pointed elsewhere first12OK
PD-17GovernMaintain the register: every document with owner, tier, status, version, approval date and next review datePF-11CA/RIThe Policy Register & Review Schedule: the only authoritative list11OK
PD-18GovernReport document currency and acknowledgement coverage to executive management every quarterPF-12IA/RIPM-01 documents past review date; PM-02 documents in force without approval; PM-03 acknowledgement coverage; PM-04 overdue acknowledgements, from the Policy Health & Attestation Reporting Workbook11OK
PD-19GovernCheck independently that documents are approved, published, reviewed and acknowledged as the Standard requiresPF-03, PF-06, PF-09, PF-11ICIA/RIndependent review findings, at least once a year [[or as your audit plan sets]]11OK

By Document Type

For each tier of the Policy Framework Standard: who drafts, who is consulted, who approves and who communicates. The approving role is read from the matrix.

TierWhat it is forWho draftsWho is consulted (PF-07)Who approves (PF-03)Role holding the AApproving role in the matrixMatchesIf the approver owns or wrote it (PF-03)Who communicatesAcknowledged by (PF-09)Review at least every (months)
PolicyWhat the organisation commits to and why. Short, stable, written for everyone.Author for the document owner, with information securityEveryone it applies to (through representatives); [[e.g. Legal, HR, Data Protection Officer]]; information securityExecutive management (the management body, or its delegate for the top policy)Executive managementExecutive managementOKThe rest of executive management, without the member who owns or wrote itPublisher [[e.g. Internal Communications, or HR for acknowledgements]], to everyone in scopeEveryone in scope: new starters within 10 working days, after a material change within 30 calendar days of its publication, and once a year12
StandardThe specific, measurable requirements that make a policy real: settings, deadlines, minimums.Author, usually information security or the function that runs the serviceThe teams who must meet it; [[e.g. Legal, HR, Data Protection Officer]] where affectedHead of Information Security (the document owner is consulted)Information securityInformation securityOKExecutive managementPublisher, to the teams who must meet itNot acknowledged; communicated to the people who use it12
ProcedureHow a task is done, step by step, by named roles.The process owner's teamThe people who carry it out; information securityHead of Information Security (the process owner is consulted)Information securityInformation securityOKExecutive managementThe process owner, to the people who carry it outNot acknowledged; communicated to the people who use it24
GuidelineRecommended practice. Helpful, not mandatory; nobody is non-compliant for not following it.Information security, or any subject expertThe people it is written forInformation securityInformation securityInformation securityOKExecutive managementInformation security, to the people it is written forNot acknowledged; communicated to the people who use it24

Role Holders

Name who holds each role and who deputises. The counts show how much of the matrix each role carries.

RoleWhat the role does hereHeld by (post)Deputy (post)What the deputy may doAccountable for (A)Responsible for (R)
Document ownerAccountable for a document's content and its review (PF-02); presents it for approval, but never approves a document they own.[[e.g. Head of IT for the access control policy]][[Deputy post]]Another manager of the same or higher level in the same area.66
AuthorDrafts the document for its owner, runs the consultation and makes the changes a review calls for.[[whoever the owner asks to draft]][[Deputy post]]Any competent person the owner names.04
Information securityKeeps the framework, the register and the reporting; approves standards, guidelines and procedures their owners cannot approve; checks tier, format and consultation before approval.[[e.g. Head of Information Security]][[Deputy post]]A named deputy may keep the register and run the reporting. Approvals need someone of equal authority.117
Executive managementApproves policies, and standards the Head of Information Security owns or wrote; receives the quarterly report, and decides on documents far past review.[[e.g. Executive Committee, or the management body]][[Deputy post]]Acts as a body; a quorum under its terms of reference, excluding the author of the document being decided.10
Consulted functionsLegal, HR and data protection review drafts that affect them (PF-07).[[e.g. Legal, HR, Data Protection Officer]][[Deputy post]]Another member of the same function.01
PublisherPublishes approved versions, withdraws old ones and runs the acknowledgement campaigns.[[e.g. Internal Communications, or HR for acknowledgements]][[Deputy post]]Any member of the publishing team.05
Independent reviewerChecks independently that documents are approved, published, reviewed and acknowledged as the Standard requires.[[e.g. internal audit]][[Deputy post]]Another reviewer independent of the process, internal or external.11

Role Combinations

The small-organisation variant: one person may hold several roles, but nobody approves a document they own or wrote (PF-03). The first rows apply in every organisation.

CombinationVerdictWhySafeguard, or what to do instead
Approving a document you own or wroteNever acceptableThe approval is the only independent look at the document (PF-03).The conflict approver for the tier, on By Document Type, decides instead.
Approving the review outcome of a document you own or wroteNever acceptableA review that changes a document is a new approval (PF-06).As above: the conflict approver for the tier.
Independently checking documents you own or wrote, or a process you runNever acceptableThe check (PD-19) exists because nobody else looks.Another reviewer, internal or external.
Recording your own acknowledgement or marking your own team's overdue ones completeNever acceptableAcknowledgement records are evidence (PF-09); they must come from the person.The person acknowledges in the system of record; the publisher reconciles.
Document owner + AuthorAcceptable with safeguardCommon: owners often draft their own documents.They never approve a document they own or wrote; for a procedure: executive management.
Document owner + Information securityAcceptable with safeguardThe Head of Information Security often owns standards, which that role approves.A standard or guideline the Head of Information Security owns is approved by the conflict approver: for a standard, executive management; for a guideline, executive management.
Document owner + Executive managementAcceptable with safeguardExecutives own policies that executive management approves.The owner presents the policy and takes no part in the decision.
Document owner + Consulted functionsAcceptableThe HR or legal lead may own a document and be consulted on others.—
Document owner + PublisherAcceptableNo duty conflicts.—
Document owner + Independent reviewerNever acceptableThe reviewer would check documents they own.Use another reviewer, or an external one.
Author + Information securityAcceptable with safeguardInformation security drafts many standards and guidelines that it would approve.The conflict approver decides: for a standard, executive management; for a guideline, executive management.
Author + Executive managementAcceptable with safeguardAn executive may draft a policy themselves.The rest of executive management, without the member who owns or wrote it.
Author + Consulted functionsAcceptableLegal or HR may draft the parts that concern them.Another member of the function reviews those parts (PD-05).
Author + PublisherAcceptableNo duty conflicts.—
Author + Independent reviewerNever acceptableThe reviewer would check documents they wrote.Use another reviewer, or an external one.
Information security + Executive managementAcceptableA head of information security may sit on the executive committee.Where they own or wrote a policy, they take no part in approving it.
Information security + Consulted functionsAcceptableNo duty conflicts.—
Information security + PublisherAcceptableIn small organisations the IT or security lead publishes documents and runs acknowledgements.—
Information security + Independent reviewerNever acceptableThe reviewer would check the register and reports they keep.Use internal audit, or an external reviewer once a year.
Executive management + Consulted functionsAcceptableNo duty conflicts.—
Executive management + PublisherAcceptablePossible in very small organisations.—
Executive management + Independent reviewerNever acceptableThe reviewer would check approvals they gave.Use internal audit reporting to the board, or an external reviewer.
Consulted functions + PublisherAcceptableHR is often consulted and also runs acknowledgements.—
Consulted functions + Independent reviewerAcceptableInternal audit is often consulted on drafts; being consulted does not stop an independent check.—
Publisher + Independent reviewerNever acceptableThe reviewer would check acknowledgement records they keep.Use another reviewer, or an external one.

Combined Roles Check

One row per person who holds more than one role. Mark each role they hold; the Result shows whether the combination is allowed.

ExamplePerson or postDocument ownerAuthorInformation securityExecutive managementConsulted functionsPublisherIndependent reviewerRoles heldNever-acceptable pairsPairs needing a safeguardResultFirst pair to resolve
EXAMPLEChief Operating Officer (owns ISP-001); on the Executive CommitteeYesYes201Allowed with safeguardDocument owner + Executive management (safeguard)
EXAMPLEHead of IT (owns AUP-001, ACP-001, RMT-GDL); drafts themYesYes201Allowed with safeguardDocument owner + Author (safeguard)
EXAMPLEHead of Information Security (owns INC-001, VMS-001, EXC-STD); drafts themYesYesYes303Allowed with safeguardDocument owner + Author (safeguard)
EXAMPLEHR Director (owns JML-PRC); consulted; runs acknowledgementsYesYesYes300OK
EXAMPLEIT Operations Manager (owns BKP-001); proposed as independent reviewerYesYes210Conflict — move a roleDocument owner + Independent reviewer (never)

Lists

RACIYesNoVerdict
RYesNever acceptable
ANoAcceptable with safeguard
A/RAcceptable

C

I

Definitions

Definitions

TermMeaning in this workbook
R — ResponsibleDoes the work. There may be more than one.
A — AccountableOwns the outcome and signs it off. Exactly one per activity, so there is never doubt about who decides.
C — ConsultedAsked for input before the activity is done.
I — InformedTold of the outcome after the activity is done.
A/RAccountable and also does the work. Counts as both an A and an R in the Check column.
Document ownerAccountable for a document's content and its review (PF-02); presents it for approval, but never approves a document they own. [[e.g. Head of IT for the access control policy]]
AuthorDrafts the document for its owner, runs the consultation and makes the changes a review calls for. [[whoever the owner asks to draft]]
Information securityKeeps the framework, the register and the reporting; approves standards, guidelines and procedures their owners cannot approve; checks tier, format and consultation before approval. [[e.g. Head of Information Security]]
Executive managementApproves policies, and standards the Head of Information Security owns or wrote; receives the quarterly report, and decides on documents far past review. [[e.g. Executive Committee, or the management body]]
Consulted functionsLegal, HR and data protection review drafts that affect them (PF-07). [[e.g. Legal, HR, Data Protection Officer]]
PublisherPublishes approved versions, withdraws old ones and runs the acknowledgement campaigns. [[e.g. Internal Communications, or HR for acknowledgements]]
Independent reviewerChecks independently that documents are approved, published, reviewed and acknowledged as the Standard requires. [[e.g. internal audit]]
ApproverNot a separate column: the approver is set per tier — Policy: executive management (the management body, or its delegate for the top policy); Standard: Head of Information Security (the document owner is consulted); Procedure: Head of Information Security (the process owner is consulted); Guideline: information security — and the approval rows put the A on the role that holds it.
TierOne of the four levels of security document: Policy, Standard, Procedure, Guideline (PF-01).
Conflict approverWho approves a document when the tier's approver owns or wrote it (PF-03). Shown on By Document Type.
TriggerAn event that forces a review before the scheduled date (PF-06).
DeputyThe person who acts for a role holder while they are absent, with no more authority than the role holds.
Never acceptableA combination that defeats the purpose of a control. Move one of the roles to someone else.
Acceptable with safeguardA combination that is workable if the safeguard shown is applied and recorded.
EXAMPLE rowA worked example on Combined Roles Check, from the example organisation's register. Delete before approval.
PF-01 … PF-12Rule numbers in the Policy Framework Standard. PM-01 … PM-04 are its headline measures.
ExceptionA deviation from any document, handled under the Security Exception & Waiver Standard (PF-10), never by informal agreement.

Framework References

Framework references

These references indicate relevance only and do not reproduce the text of any standard.

FrameworkReferenceSupported by
ISO/IEC 27001:2022Clause 5.3 — Organizational roles, responsibilities and authoritiesResponsibility Matrix and Role Holders
ISO/IEC 27001:2022Annex A 5.2 — Information security roles and responsibilitiesResponsibility Matrix: one accountable role per activity
ISO/IEC 27001:2022Annex A 5.4 — Management responsibilitiesApproval rows PD-06 to PD-09; quarterly report PD-18
NIST CSF 2.0GV.RR-02 — “Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced”Responsibility Matrix, By Document Type and Role Holders
DORA — Delegated Regulation (EU) 2024/1774Article 2(2)(i) — roles and responsibilities for developing, implementing and maintaining the policiesWhole workbook: roles for developing, implementing and maintaining policies
NIS2 — Directive (EU) 2022/2555Article 20(1) — management bodies approve the cybersecurity risk-management measures and oversee their implementationPolicy approval row PD-06: executive management or the management body

Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Delegated Regulation (EU) 2024/1774