Back to Blog
ISO/IEC 27001:2013 Annex A.6 — Organization of Information Security
Cybersecurity, GRC, ISO 27001

ISO/IEC 27001:2013 Annex A.6 — Organization of Information Security

By BlackTrace Software and Cyber Defense

ISO/IEC 27001:2013 Annex A.6 — Organization of Information Security

Cybersecurity is not only about having the right technology. It also requires the right structure, ownership, and accountability.

ISO/IEC 27001:2013 Annex A.6 — Organization of Information Security focuses on how organizations establish the internal framework needed to manage information security effectively.

This means clearly defining responsibilities, coordinating security activities across the organization, separating conflicting duties, integrating security into projects, and maintaining appropriate relationships with external parties.

What Annex A.6 Focuses On

Annex A.6 provides a framework for establishing an information security management structure, defining roles and responsibilities, and ensuring effective coordination within the organization.

The objective is to establish a management framework and ensure information security is embedded into the organization’s processes and culture.

Key Areas of Annex A.6

  • A.6.1 Internal Organization: Define an information security management structure.
  • A.6.2 Mobile Device Policy: Establish policies and controls for the use of mobile devices.
  • A.6.3 Information Security in Project Management: Ensure information security is integrated into project management.
  • A.6.4 Information Security Responsibilities: Define and communicate information security responsibilities.
  • A.6.5 Segregation of Duties: Separate conflicting duties to reduce the risk of error or fraud.
  • A.6.6 Contact with Authorities: Establish appropriate contact with relevant authorities.
  • A.6.7 Information Security in Supplier Relationships: Ensure information security requirements are addressed with suppliers.

Why Organization Matters in Information Security

The bigger lesson is simple:

Strong security starts with strong governance.

When nobody clearly owns a security responsibility, important tasks can be missed. When security operates separately from business processes, risk increases. A mature security program makes information security part of everyday decision-making rather than something addressed only after an incident.

Key Benefits

  • Establishes clear governance and accountability
  • Ensures information security roles and responsibilities are understood
  • Integrates security into business processes and projects
  • Reduces risk through structured policies and controls
  • Supports compliance with legal and regulatory requirements

Key Principles

  • Accountability: Everyone has defined responsibilities.
  • Integration: Security is part of every process.
  • Collaboration: Teams work together across all levels.
  • Compliance: Organizations meet legal, contractual, and regulatory obligations.

Practical Examples of Implementation

  • Establish an Information Security Steering Committee.
  • Define and approve information security policies.
  • Include security requirements in project plans and change management.
  • Conduct regular role and responsibility reviews.
  • Assess suppliers for security compliance.

Final Thought

Technology provides capabilities. Governance determines how those capabilities are managed.

At BlackTrace Software and Cyber Defense, our approach is built around the connection between governance, risk, compliance, cybersecurity, and technology. Effective security should be structured, measurable, accountable, and integrated into the organization.

Strong governance. Clear responsibility. Better security.