1. Direct involved employees: Employee with defined responsibilities for managing, planning, implementation, operation, and maintenance of the ISMS. For example, management review and security forum participants, IT staff, and those conducting risk assessments, internal audits, and ISMS awareness training.