Back

Establish, implement, and maintain an organizational structure.


CONTROL ID
16310
CONTROL TYPE
Establish/Maintain Documentation
CLASSIFICATION
Preventive

SUPPORTING AND SUPPORTED CONTROLS




This Control directly supports the implied Control(s):
  • Analyze organizational objectives, functions, and activities., CC ID: 00598

There are no implementation support Controls.


SELECTED AUTHORITY DOCUMENTS COMPLIED WITH




  • There is a definition and documentation of an adequate information security structure within the organization. (1.2.2 Requirements (should) Bullet 1, Information Security Assessment, Version 5.1)
  • Management should establish an organizational structure, assign responsibility, and delegate authority to achieve the entity’s objectives. (3.01, Standards for Internal Control in the Federal Government)