Skip to main content

Deep Dive - Job Descriptions

Learn about the Job Descriptions control and associated evidence items

Micah Spieler avatar
Written by Micah Spieler
Updated over 2 years ago

What is the Job Descriptions control?

Strike Graph's default control language is: "Job descriptions are in place for all IT staff which define required skills and responsibilities as they relate to information security. The job descriptions are available to all employees."

This language should be customized to reflect the specific process that your organization has defined. It's important that your stated control description accurately reflects how your organization implements this control.

Which framework is this for?

SOC 2, ISO 27001

Why is this control important?

This control demonstrates that information security concepts are pervasive throughout the organization and that competent individuals perform key responsibilities. Job descriptions are often the best evidence to demonstrate this organizational competence. Job descriptions also demonstrate that information security responsibilities are defined (ISO 27001, Annex 6.1.1).

Who’s involved with this control?

Typical control owner: HR Lead

Typical parties involved: Department managers

How often should I perform this control?

Typical frequency: Continuous

How do I demonstrate this control?

While everyone in the organization should have a commitment to information security within their job description, most auditors will sample and test to ensure that members of the IT team have specific roles and responsibilities included within their job descriptions. They may also look for information security responsibilities in the job descriptions of upper management, not just in IT.

  • Ensure that the job descriptions for your head of IT (CISO, CTO, VP Technology, etc.) mention their roles and responsibilities concerning information security. This will typically include words like oversight, management of the information security program, responsibility for developing and monitoring the IT security program, or other similar functions.

  • Ensure the IT department’s job descriptions include each position's roles and responsibilities concerning information security. The language within the job description might include the following:

    • "Adhere to all information security policies and procedures."

    • "Develop code with best-in-class security features."

    • or other security-focused language.

In addition to sprinkling this language throughout job descriptions, post the descriptions in a place on your network where all employees can see them. Some organizations post them on a confluence page or in an open folder on a shared drive and ensure that only HR can edit the content.

Did this answer your question?