Skip to main content

Roles & Responsibilities Policy (Security RACI)

Document control

FieldValue
OwnerRon Benisty — CTO & CSO (ron.b@iontwrks.com)
StatusApproved
Version1.0
ClassificationConfidential
Approved byRon Benisty — CTO & CSO
Approval date2026-05-26 (Tuesday)
Last reviewed2026-05-26
Review cycleAnnual — next review due May 2027
Parent policySecure SDLC (SSDLC)

Satisfies ISO/IEC 27001:2022 A.5.2 (information-security roles & responsibilities), supports SOC 2 CC1.1–CC1.5 (control environment) and NIST SSDF PO.2 (organizational roles). Closes Gap 13 of the SSDLC gap analysis.


1. Purpose

State unambiguously who is accountable, responsible, consulted, and informed for each SSDLC activity. Resolves the "everyone or no-one" ambiguity that Type II testing flags when control ownership is unclear.

2. Parties

PartyDescription
CTO & CSORon Benisty (ron.b@iontwrks.com). Single accountable owner for the SSDLC, every sibling policy, and every Type II control. Final approver for changes to the SSDLC, the security toolchain, and exception requests.
S.E.T teamThe internal team with Admin / production access. Holds branch-protection admin, AWS IAM users, WorkOS admin, Logz.io admin, Cloudflare admin. Operates the platform and approves contractor PRs.
Third-party dev firmThe contracted development firm. Write-only GitHub collaborators (no AWS access). Subject to all controls in Supply Chain & CI/CD Security.
Contractor developersNamed individuals within the dev firm. Bound by NDA, DPA, MFA, and the dev firm's contractual security clauses.
MSSP customersThe MSSPs who purchase S.E.T (Admin portal users). Manage their own client/vendor data within their tenant; subject to S.E.T's customer DPA.
MSSP's clientsEnd-customers of the MSSPs (Customer portal users). Indirect parties; their primary relationship is with the MSSP, not S.E.T.
Sub-processorsWorkOS, Logz.io, AWS, Cloudflare, GitHub, and any tool added later. Listed in the customer DPA.

3. RACI — SSDLC activities

R = Responsible (does the work) · A = Accountable (one party, owns the outcome) · C = Consulted (input before the decision) · I = Informed (after the decision)

ActivityCTO & CSOS.E.T teamDev firmSub-processors
Maintain SSDLC + sibling policiesARI
Write application codeCRR
Submit pull requestIRR
CODEOWNER review / approve PRAR
Merge to develop (nonprod)ARI
Promote to main (production)AR
Manage GitHub org & accessAR
Manage AWS IAM & cloud accessAR
Operate the security toolchain (scanners, Harden-Runner, etc.)ARI
Triage CI security findingsARC
Threat modeling (per feature / epic)ARC
Run pen-tests / DASTARIC (external vendor)
Vulnerability remediation (SLA-tracked)ARR
Incident responseARII
Root-cause analysisARC
Backup verification & DR drillsARI
Access reviews (monthly + quarterly + annual)AR
Evidence collection & retentionARI
Developer security training — S.E.T teamAR
Developer security training — dev firmCIA · R
Risk assessmentARC
Customer breach notification (Amendment 13 + DPA)ARI
Sub-processor onboarding / DPAARII
Tenant decommissioningARI
Cryptography standard upkeepARC
Audit response (SOC 2, ISO 27001, customer right-to-audit)ARII

4. Small-team note

S.E.T's internal team is small (see Separation of Duties §4). Where Accountable and Responsible collapse onto the same person, the compensating controls in that policy apply: branch-protection cannot be bypassed, deployments are automated via OIDC, audit logs are immutable, and four-eyes promote on production where staffing allows.

5. Right-sized expectations

This RACI reflects S.E.T at MVP scale (one CTO & CSO, a small S.E.T team, one third-party dev firm). It will be re-issued — not just re-reviewed — when:

  • The team grows (a dedicated Security Engineer, an SRE function, an in-house IR rota).
  • Phase 2 brings Nimbus customers into AWS Tel Aviv (Environments) — additional cloud-residency duties appear.
  • A new sub-processor is introduced.

6. Document change history

VersionDateAuthorDescription of changeApproved by
1.02026-05-26Ron Benisty (CTO & CSO)Initial version — establishes the SSDLC RACI.Ron Benisty (CTO & CSO)