Management responsibility
Also known as: management accountability, leadership accountability
The duty of top leaders to own, approve and be able to show the organisation's security work.
Draft - this entry has not been reviewed yet.
Formal
The duty in NIS2 Article 20 for the management body to approve the security measures, oversee how they are carried out and take part in training, with members liable if they fail; ISO 27001 clause 5 sets a similar leadership duty.
In plain English
The captain answers for the ship - the crew may do the work, but when it hits the rocks the captain cannot say "that was not my job".
In practice
The chief executive of a Danish municipality signs off the risk assessment each year, attends a half-day course on cyber risk with the rest of the management team and gets a status report from the security lead every quarter.
Why it matters
When leaders do not own security, it loses out in every budget round; making them personally answerable moves it from the server room to the boardroom.
Technical deep dive
NIS2 Article 20(1) requires member states to ensure that the management bodies of essential and important entities approve the cybersecurity risk-management measures taken under Article 21, oversee their implementation and can be held liable for infringements of that article. Article 20(2) requires members of the management body to follow training and encourages entities to offer similar training to employees regularly, so that leaders can identify risks and assess risk-management practices. The directive does not define "management body"; national company law decides, which in Denmark's two-tier model can mean both the board (bestyrelse) and the executive management (direktion). The Danish NIS2 Act implements these duties in § 7.
The enforcement side sits in the supervision articles. Articles 32(6) and 33(5) require that natural persons responsible for, or acting as legal representatives of, an entity can be held liable for breaching their duty to ensure compliance, and Article 32(5)(b) allows, for essential entities only and only after other measures have failed, a temporary ban on a person at CEO or legal-representative level from exercising managerial functions. The Danish act contains the corresponding power in § 23. Similar thinking appears elsewhere: DORA Article 5(2) makes the management body of a financial entity bear ultimate responsibility for ICT risk, and GDPR Articles 5(2) and 24 place accountability on the controller as an organisation.
ISO/IEC 27001:2022 expresses the same idea in management-system terms. Clause 5.1 lists what top management must demonstrate, from ensuring that the policy and objectives fit the strategic direction and that resources are available, to directing people, promoting continual improvement and supporting other managers in their areas. Clause 5.2 makes top management establish the policy, 5.3 makes it assign and communicate roles, and 9.3 requires it to review the ISMS at planned intervals and record decisions.
The recurring misconception is that the duty can be delegated. Execution can be delegated to a CISO, an IT department or a managed service provider; approval, oversight and accountability cannot. In practice supervisors and auditors look for evidence rather than statements: minutes in which the board approved the measures and a risk appetite, dated training records for each member, periodic reporting with decisions attached, and follow-up on audit findings. A signature on a policy document that the board never discussed rarely satisfies either an auditor or a supervisory authority.
What to learn first
Everything this builds on, foundations first.
- CIA triad
- →Threat
- →Asset
- →Vulnerability
- →Impact
- →Likelihood
- →Risk
- →Risk management
- →Management responsibility
Relationships
- Part of
- Governance
- Requires
- Risk management
Sources & further reading
Standards & official texts
- Directive (EU) 2022/2555 (NIS2 Directive), Article 20 · European Union
- ISO/IEC 27001:2022, Clause 5 (Leadership) · ISO/IEC
Course material
- Cyber Security Fast Track - Ordliste
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Check yourself
Loading…