27001 Clause 5.327001 A.5.227001 A.5.442001 Clause 5.342001 A.3.242001 A.10.242001 A.4.6
Review. Reviewed when the number of people running the service changes, and otherwise at least once every 90 days.
Who is accountable for what, and an honest statement of what a single operator can and cannot separate.
27001 Clause 5.327001 A.5.227001 A.5.442001 Clause 5.342001 A.3.242001 A.10.242001 A.4.6Review. Reviewed when the number of people running the service changes, and otherwise at least once every 90 days.
The service is built and run by one person, who holds every role named below. Naming them separately is still useful, because it makes clear which hat is being worn when a decision is taken and which evidence that decision should leave behind.
Owner — decides scope, accepts risk, approves this policy set, and is the only party who can raise the spend limit or change what the service does.
Operator — runs the service: deploys, responds to incidents, works the control panel, and files the receipts that record each control action.
Developer — writes and reviews the code, and is responsible for the secure development practice recorded in the change management processes.
Responder — receives security reports through the public intake and decides whether a report becomes an incident.
Taking the game down is an authenticated control action available to the Operator, and every use of it writes a receipt into the control history chain. The public security report intake can also take the game down, which is deliberate: a reporter can demonstrate impact without needing credentials.
Changing what the service does requires a deployment, and every deployment is recorded in the change record with an identifier and a classification. There is no path to production that bypasses that record.
Segregation of duties cannot be achieved with one person, and this document does not claim it. The mitigation is that actions are made evident rather than prevented: control actions write receipts into a hash chain anchored outside the table it summarises, deployments appear in the public change record, and the tank logs are deterministic and replayable.
That is detection, not separation. It is recorded as a limitation of scope, and it is why the independent review and internal audit clauses remain open on the register rather than being asserted here.
Competence is not evidenced by certificates held. It is claimed on the basis of the work product itself: the change record, the incident record with causes and durations, and the register's own honesty about what is missing.
This is a weaker form of evidence than the clause envisages, and the register records the competence and awareness clauses as open rather than met.