Tracecat
Govern
GV.RR

Roles, Responsibilities, and Authorities

Cybersecurity roles, responsibilities, and authorities to foster accountability, performance assessment, and continuous improvement are established and communicated

Tools for roles, responsibilities, and authorities

Hosted MCP servers your agents can use for these controls.

Starter prompts

Paste into Claude Code, Microsoft Copilot, or Codex connected to Tracecat MCP, and build it out together.

Generate a security RACI from reality

Build me a workflow in Tracecat that drafts our security RACI from observed reality. Pull who actually handles cases from Tracecat assignments, who carries the pager from PagerDuty schedules, and who holds admin roles from Okta. Have an agent assemble the draft RACI in Notion, flag responsibilities with no named owner, and flag people who hold authority with no documented responsibility. First help me understand how this maps to GV.RR-02 and why a RACI built from real activity beats one written in a workshop. Ask me which security functions to cover first. Talk me through how to handle the gaps the draft exposes without turning the exercise into blame.

Track security workload and resourcing

Build me a resourcing report in Tracecat. Each month, measure case volume per analyst, backlog age, after-hours pages from PagerDuty, and the work that sat untouched. Have an agent turn the numbers into a short resourcing brief that compares the workload against our documented roles, and post it to the leadership channel. First help me understand how this maps to GV.RR-03 and how workload evidence supports resource allocation arguments. Ask me what headcount and tooling constraints we are working within. Talk me through which trends signal under-resourcing versus process problems.

Wire security into HR lifecycle events

Build me an automation in Tracecat that hooks security into HR lifecycle events. On hire, confirm security training is assigned and the right group memberships were granted in Okta. On role change, re-check access against the new role. On exit, verify every account and credential was revoked within the agreed window and open a Linear issue for anything that lingers. First help me understand how this maps to GV.RR-04 and where HR practices usually leak security obligations. Ask me how I get notified of hires, role changes, and exits today. Talk me through which checks should block and which should just report.

Controls

  • GV.RR-01
    PM-2
    PM-19
    PM-23
    PM-24
    PM-29

    Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving

  • GV.RR-02
    PM-2
    PM-13
    PM-19
    PM-23
    PM-24
    PM-29

    Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced

  • GV.RR-03
    PM-3

    Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies

  • GV.RR-04
    PM-13
    PS-1
    PS-7
    PS-9

    Cybersecurity is included in human resources practices

Control text and SP 800-53 Rev 5 references from the official NIST CSF 2.0 and OLIR releases.

Automate roles, responsibilities, and authorities with agents

Paste an example into your coding assistant and an agent builds the automation around your tools.

All controls