# Decision Authority Matrix for Security Risks - **PURPOSE:** Helps organizations clearly define who has authority and responsibility for different types of security risk decisions, preventing both decision paralysis and authority conflicts. - **WHEN TO USE:**When establishing a new security governance structure, resolving recurring authority conflicts, or following organizational changes that impact security decision-making. ## Decision Authority Matrix | Decision Type | Board | CEO | CIO | CISO | Business Executives | Security Team | | --- | --- | --- | --- | --- | --- | --- | | STRATEGIC DECISIONS | | | | | | | | Security Strategy | A | R | C | R | C | C | | Risk Appetite | A | R | C | R | C | C | | Security Budget | I | A | R | R | C | C | | OPERATIONAL DECISIONS | | | | | | | | Security Policies | I | I | C | A/R | C | R | | Exception Approvals | | | I | A | R | R | | Risk Acceptance | | | I | C | A/R | R | | Security Controls | | | I | A | C | R | | INCIDENT RESPONSE | | | | | | | | Critical Incidents | I | I | I | A | I | R | | Major Incidents | | I | I | A | I | R | | Routine Incidents | | | I | A | I | R | Table 45: Decision Authority Matrix ### Legend: **R =** Responsible (does the work) **A =**Accountable (ultimately answerable) **C =**Consulted (provides input) **I =**Informed (receives information) ## ESCALATION THRESHOLDS: 1. Tier 1: Risks with potential impact < $100,000 - CISO decision 2. Tier 2: Risks with potential impact $100,000-$1M - Executive Committee approval 3. Tier 3: Risks with potential impact > $1M - Board Risk Committee approval ## EXCEPTION PROCESS: - [ ] Business unit documents exception request with business justification - [ ] Security team assesses risk impact and recommends controls - [ ] Approval at appropriate level based on risk impact - [ ] Documentation and tracking of all approved exceptions - [ ] Periodic review of all active exceptions (quarterly minimum) ## IMPLEMENTATION TIPS: - Customize thresholds based on your organization's size and risk profile - Review the matrix annually and after significant organizational changes - Use this as a communication tool with both security and business stakeholders *** (c)[Kayne McGladrey](https://kaynemcgladrey.com/) - [Get the full book "Cyber Risk is a Myth"](https://www.routledge.com/Cyber-Risk-is-a-Myth-A-Business-Approach-to-Integrated-Risk-Management/McGladrey/p/book/9781041249054)