Skip to content

Information Security Roles, Responsibilities and Authorities

Purpose. Defines who is responsible and accountable for information security at Soon and the authorities assigned to each role (ISO/IEC 27001:2022 5.1, 5.3 and A.5.2). It removes ambiguity about "who owns what" across the ISMS.

Status: DRAFT. Role-holders confirmed at the 2026-06-25 working session, with founders/shareholders confirmed 2026-07-03. Soon is a small, fully-remote team, so individuals hold multiple roles; this is acceptable provided conflicts of interest are managed (see Segregation of Duties, A.5.3).

1. Roles and responsibilities

1.1 Top management — Olaf Jacobson, Thomas Picauly, Melvin Jacobson, Alessandro Cardinali

Soon's four founders and shareholders. TODO(owner: Olaf): exact employment/contract construct per founder (employee vs DGA/management fee vs ZZP) not yet documented. Accountable for the ISMS overall. Responsibilities: - Establish the information security policy and objectives; ensure they fit Soon's direction. - Provide the resources needed for the ISMS. - Approve the Information Security Policy, the Statement of Applicability and the Risk Treatment Plan. - Accept residual risk and review the ISMS at management reviews. - Promote a culture of security and continual improvement.

1.2 Information Security Manager (ISM) — Olaf Jacobson

Runs the ISMS day-to-day and is the main point of contact for the auditor. Responsibilities: - Maintain the ISMS documentation, this repository and the document lifecycle. - Own the Risk Assessment & Treatment Process; consolidate risks and treatment for management review. - Coordinate internal audits and management reviews; track nonconformities and corrective actions. - Maintain the asset inventory, SoA, supplier and legal registers (with input from owners). - Drive security awareness; act as coordination lead for security incidents. - Authority to declare a security incident and convene response.

1.3 Technical / Infrastructure Security Lead — Thomas Picauly

Owns the technical security of the platform and cloud. Responsibilities: - Security of AWS, GCP and Azure environments, networks and configuration. - Implement and operate the A.8 technological controls: access control & authentication, cryptography, logging/monitoring, vulnerability & patch management, backups, malware protection, secure configuration. - Primary risk owner for technical/infrastructure risks; technical lead during incidents. - Authority to grant/revoke production access (per the Access Control Policy) and to approve technical changes (per the Change Management Process).

1.4 Data Protection / Privacy Owner — Olaf Jacobson (no formal DPO)

Soon is a data processor; a formal DPO is not assessed as legally required at the current size, but the responsibility is explicitly owned: - Own GDPR processor obligations: DPAs/sub-processor list, records of processing, data-subject request support, personal-data breach notification (incl. the 72-hour duty). - Maintain the Privacy and Personal Data Protection Policy. - TODO(owner): re-assess the need for a formal DPO as Soon grows or if processing risk increases.

1.5 Risk owners and asset owners

  • Risk owners — accountable for assigned risks in the Risk Assessment Report and delivering their treatment. Default split: Thomas (technical risks), Olaf (governance, privacy, supplier, people risks). Confirmed so far: Thomas owns backup verification (R-15 specifics), environment segregation (R-09), and AI sub-processor review (feeds A.5.34). TODO(owner): confirm remaining risks individually.
  • Asset owners — accountable for assets in the Information Asset Inventory; named per asset (several TODO(owner)).

1.6 All personnel and contractors

  • Comply with ISMS policies (Acceptable Use, Remote Working, etc.).
  • Report security events promptly per the Event Reporting Procedure.
  • Complete security awareness training; protect credentials and devices (BYOD).

1.7 External security consultant — Andrea Cardinali (CyberSquad)

Advisory role: supports policy development, internal audit structure, pentest sourcing and ISMS guidance. Leads the ISO/IEC 27001 certification engagement (via his own network of accredited contacts). Not an accountable internal role and not the ISM; accountability for all decisions remains with Soon.

Related-party note (confirmed 2026-07-03): Andrea is the younger brother of founder/shareholder Alessandro Cardinali. This does not disqualify him from the advisory or internal-audit role, but is documented here transparently. Internal audit independence is preserved because Andrea is external to and independent of the ISM (Olaf) who operates the ISMS day-to-day — see §2, "internal audit" row.

2. RACI for key ISMS activities

R = Responsible (does the work) · A = Accountable (final sign-off) · C = Consulted · I = Informed. TM = Top management · ISM = Olaf · TECH = Thomas · DPO = Privacy owner (Olaf) · EXT = Andrea (consultant).

Activity TM ISM TECH DPO EXT
Approve Information Security Policy A R C C C
Maintain ISMS documents & SoA I A/R C C C
Risk assessment & treatment A R C C C
Accept residual risk A R C C I
Grant/revoke production access I C A/R I
Approve changes I C A/R I
Incident response I A R C C
Personal-data breach notification A C C R C
Internal audit A C I I R
Management review A R C C C
Supplier security assessment I A C C C
Security awareness training I A/R C C C

Note the deliberate split for internal audit: Andrea (EXT) performs it so it is independent of the ISM who runs the ISMS (auditors expect this independence).

3. Authorities (summary)

Decision Authority
Approve policies / SoA / treatment plan Top management
Accept residual risk Top management (on ISM recommendation)
Grant production / privileged access Technical Security Lead (per Access Control Policy)
Approve production changes Technical Security Lead (per Change Management Process)
Declare a security incident ISM or Technical Security Lead
Notify a personal-data breach to authorities/subjects Data Protection / Privacy Owner

Change log

Version Date Author Comments
0.1 2026-06-25 Andrea Cardinali / ISMS First draft — roles confirmed (Olaf ISM/top-mgmt/privacy; Thomas technical security lead; Andrea advisory). Co-founder names and per-risk owners pending.
0.2 2026-07-03 Olaf Jacobson Named all four founders/shareholders (top management); documented Andrea/Alessandro sibling relationship; confirmed Thomas as owner of backup, environment-segregation and AI sub-processor risks.