graphgrc

SCF - TPM-05.4 - Responsible, Accountable, Supportive, Consulted & Informed (RASCI) Matrix

Mechanisms exist to document and maintain a Responsible, Accountable, Supportive, Consulted & Informed (RASCI) matrix, or similar documentation, to delineate assignment for cybersecurity & data privacy controls between internal stakeholders and External Service Providers (ESPs).

Mapped framework controls

ISO 27001

ISO 27002

Control questions

Does the organization document and maintain a Responsible, Accountable, Supportive, Consulted & Informed (RASCI) matrix, or similar documentation, to delineate assignment for cybersecurity & data privacy controls between internal stakeholders and External Service Providers (ESPs)?