---
sourceDocument: Yokohama Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/governance-risk-compliance

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Fields on the Roles and Responsibilities tab

# Fields on the Roles and Responsibilities tab {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

On the Roles and Responsibilities tab, you specify the responsibilities of various stakeholders during the review and approval process.

## Fields on the Roles and Responsibilities tab {#cam-form-roles-responsibility-tab__id_gbf_lqf_3cc}

CAM roles that are required for particular tasks are listed in [CAM user roles](https://servicenow-prod.fluidtopics.net/vVcXrPdjlvURFo4tjkUmOA "Assign users and groups with roles to prepare them to user the CAM application.").
{#cam-form-roles-responsibility-tab__table-role-responsibility-tab__entry__2}

| User / Role | Description |
|-|-|
| System owner | The individual responsible for procuring, developing, integrating, modifying, operating, and maintaining an information system. |
| Authorizing Official (AO) | The individual responsible for accepting an information system into an operational environment at a known risk level. Typically, this person is at the CISO or deputy CISO level. |
| Authorizing Official Designated Representatives (AODR) | One or more AODRs. |
| Security Control Assessors (SCA) | The individuals responsible for conducting a thorough assessment of the controls of an information system. |
| Information System Security Managers (ISSM) | The individuals responsible for conducting information system security management activities as designated by the ISSO. |
| Information System Security Officers (ISSO) | The individuals responsible for ensuring that the appropriate operational security posture is maintained for an information system. |
| Information owners | The individuals responsible for statutory, management, and operational authority. |
| System users | The users responsible for performing the actual work on the system. |
[Table 1. Roles and Responsibilities tab]

{#cam-form-roles-responsibility-tab__table-role-responsibility-tab}

