Information Security Roles, Responsibilities and Authorities¶
Purpose. Defines who is responsible and accountable for information security at Soon and the authorities assigned to each role (ISO/IEC 27001:2022 5.1, 5.3 and A.5.2). It removes ambiguity about "who owns what" across the ISMS.
Status: DRAFT. Role-holders confirmed at the 2026-06-25 working session, with founders/shareholders confirmed 2026-07-03. Soon is a small, fully-remote team, so individuals hold multiple roles; this is acceptable provided conflicts of interest are managed (see Segregation of Duties, A.5.3).
1. Roles and responsibilities¶
1.1 Top management — Olaf Jacobson, Thomas Picauly, Melvin Jacobson, Alessandro Cardinali¶
Soon's four founders and shareholders. TODO(owner: Olaf): exact employment/contract
construct per founder (employee vs DGA/management fee vs ZZP) not yet documented.
Accountable for the ISMS overall. Responsibilities:
- Establish the information security policy and objectives; ensure they fit Soon's direction.
- Provide the resources needed for the ISMS.
- Approve the Information Security Policy, the
Statement of Applicability
and the Risk Treatment Plan.
- Accept residual risk and review the ISMS at management reviews.
- Promote a culture of security and continual improvement.
1.2 Information Security Manager (ISM) — Olaf Jacobson¶
Runs the ISMS day-to-day and is the main point of contact for the auditor. Responsibilities: - Maintain the ISMS documentation, this repository and the document lifecycle. - Own the Risk Assessment & Treatment Process; consolidate risks and treatment for management review. - Coordinate internal audits and management reviews; track nonconformities and corrective actions. - Maintain the asset inventory, SoA, supplier and legal registers (with input from owners). - Drive security awareness; act as coordination lead for security incidents. - Authority to declare a security incident and convene response.
1.3 Technical / Infrastructure Security Lead — Thomas Picauly¶
Owns the technical security of the platform and cloud. Responsibilities: - Security of AWS, GCP and Azure environments, networks and configuration. - Implement and operate the A.8 technological controls: access control & authentication, cryptography, logging/monitoring, vulnerability & patch management, backups, malware protection, secure configuration. - Primary risk owner for technical/infrastructure risks; technical lead during incidents. - Authority to grant/revoke production access (per the Access Control Policy) and to approve technical changes (per the Change Management Process).
1.4 Data Protection / Privacy Owner — Olaf Jacobson (no formal DPO)¶
Soon is a data processor; a formal DPO is not assessed as legally required at the
current size, but the responsibility is explicitly owned:
- Own GDPR processor obligations: DPAs/sub-processor list, records of processing, data-subject
request support, personal-data breach notification (incl. the 72-hour duty).
- Maintain the Privacy and Personal Data Protection Policy.
- TODO(owner): re-assess the need for a formal DPO as Soon grows or if processing risk increases.
1.5 Risk owners and asset owners¶
- Risk owners — accountable for assigned risks in the Risk Assessment Report
and delivering their treatment. Default split: Thomas (technical risks), Olaf (governance,
privacy, supplier, people risks). Confirmed so far: Thomas owns backup verification
(R-15 specifics), environment segregation (R-09), and AI sub-processor review
(feeds A.5.34).
TODO(owner): confirm remaining risks individually. - Asset owners — accountable for assets in the Information Asset Inventory;
named per asset (several
TODO(owner)).
1.6 All personnel and contractors¶
- Comply with ISMS policies (Acceptable Use, Remote Working, etc.).
- Report security events promptly per the Event Reporting Procedure.
- Complete security awareness training; protect credentials and devices (BYOD).
1.7 External security consultant — Andrea Cardinali (CyberSquad)¶
Advisory role: supports policy development, internal audit structure, pentest sourcing and ISMS guidance. Leads the ISO/IEC 27001 certification engagement (via his own network of accredited contacts). Not an accountable internal role and not the ISM; accountability for all decisions remains with Soon.
Related-party note (confirmed 2026-07-03): Andrea is the younger brother of founder/shareholder Alessandro Cardinali. This does not disqualify him from the advisory or internal-audit role, but is documented here transparently. Internal audit independence is preserved because Andrea is external to and independent of the ISM (Olaf) who operates the ISMS day-to-day — see §2, "internal audit" row.
2. RACI for key ISMS activities¶
R = Responsible (does the work) · A = Accountable (final sign-off) · C = Consulted · I = Informed. TM = Top management · ISM = Olaf · TECH = Thomas · DPO = Privacy owner (Olaf) · EXT = Andrea (consultant).
| Activity | TM | ISM | TECH | DPO | EXT |
|---|---|---|---|---|---|
| Approve Information Security Policy | A | R | C | C | C |
| Maintain ISMS documents & SoA | I | A/R | C | C | C |
| Risk assessment & treatment | A | R | C | C | C |
| Accept residual risk | A | R | C | C | I |
| Grant/revoke production access | I | C | A/R | I | – |
| Approve changes | I | C | A/R | I | – |
| Incident response | I | A | R | C | C |
| Personal-data breach notification | A | C | C | R | C |
| Internal audit | A | C | I | I | R |
| Management review | A | R | C | C | C |
| Supplier security assessment | I | A | C | C | C |
| Security awareness training | I | A/R | C | C | C |
Note the deliberate split for internal audit: Andrea (EXT) performs it so it is independent of the ISM who runs the ISMS (auditors expect this independence).
3. Authorities (summary)¶
| Decision | Authority |
|---|---|
| Approve policies / SoA / treatment plan | Top management |
| Accept residual risk | Top management (on ISM recommendation) |
| Grant production / privileged access | Technical Security Lead (per Access Control Policy) |
| Approve production changes | Technical Security Lead (per Change Management Process) |
| Declare a security incident | ISM or Technical Security Lead |
| Notify a personal-data breach to authorities/subjects | Data Protection / Privacy Owner |
Related documents¶
- Information Security Policy (ISMS-DOC-05-4)
- Executive Support Letter (ISMS-DOC-05-3)
- Risk Assessment & Treatment Process (ISMS-DOC-06-2)
- Statement of Applicability (ISMS-FORM-06-2)
- Segregation of Duties Guidelines (ISMS-DOC-A05-3-1) — to create
Change log¶
| Version | Date | Author | Comments |
|---|---|---|---|
| 0.1 | 2026-06-25 | Andrea Cardinali / ISMS | First draft — roles confirmed (Olaf ISM/top-mgmt/privacy; Thomas technical security lead; Andrea advisory). Co-founder names and per-risk owners pending. |
| 0.2 | 2026-07-03 | Olaf Jacobson | Named all four founders/shareholders (top management); documented Andrea/Alessandro sibling relationship; confirmed Thomas as owner of backup, environment-segregation and AI sub-processor risks. |