ISMS Responsibilities
Overview
Section titled “Overview”A functioning Information Security Management System (ISMS) requires clearly defined roles and responsibilities. The requirements differ depending on the applicable standard:
- ISO 27001 and BSI IT-Grundschutz: Basic ISMS roles
- NIS2 Directive: Additional obligations, especially for executive management
Mandatory Roles According to ISO 27001 & BSI IT-Grundschutz
Section titled “Mandatory Roles According to ISO 27001 & BSI IT-Grundschutz”These roles are mandatory for every ISMS:
1. Executive Management / Senior Leadership
Section titled “1. Executive Management / Senior Leadership”Responsibilities:
- Overall responsibility for information security
- Approval of the Information Security Policy
- Provision of resources (budget, personnel, time)
- Appointment of the Information Security Officer
- Annual management review
Reference:
- ISO 27001: Clause 5.1 (Leadership and commitment)
- BSI IT-Grundschutz: ORP.1.A1
2. Information Security Officer (ISO)
Section titled “2. Information Security Officer (ISO)”Responsibilities:
- Central coordination of the ISMS
- Advisory to executive management on security matters
- Creation and maintenance of security documentation
- Monitoring implementation of security measures
- Point of contact for all security questions
Reference:
- ISO 27001: Clause 5.3
- BSI IT-Grundschutz: ORP.1.A15
Typical Time Investment: 20-50% of full-time position (depending on organization size)
3. IT Management / IT Operations
Section titled “3. IT Management / IT Operations”Responsibilities:
- Technical implementation of security measures
- Configuration and operation of IT systems
- Patch management and updates
- Incident response (technical level)
- Backup and recovery
Reference:
- ISO 27001: Clause 8 (Operation)
- BSI IT-Grundschutz: OPS.1.1.2
4. Asset Owner
Section titled “4. Asset Owner”Responsibilities:
- Responsibility for specific information assets
- Classification of protection requirements
- Approval of access rights
- Monitoring proper use
Examples: Head of Finance (owner of financial data), Production Manager (owner of control systems)
Reference:
- ISO 27001: Annex A.5.9 (Inventory of information and other associated assets)
- BSI IT-Grundschutz: ORP.4
5. Process Owner
Section titled “5. Process Owner”Responsibilities:
- Responsibility for the security of a business process
- Integration of security requirements into the process
- Business Impact Analysis (BIA) for the process
- Approval of process-specific security measures
Examples: Sales Manager (owner of sales process), Production Manager (owner of production process)
Reference:
- ISO 27001: Clause 6.1.2 (Information security risk assessment)
- BSI IT-Grundschutz: ORP.1
6. Data Protection Officer (DPO)
Section titled “6. Data Protection Officer (DPO)”Special Note: Mandatory for public authorities and certain private organizations under GDPR Art. 37
Responsibilities:
- Monitoring GDPR compliance
- Advisory on data protection matters
- Training and awareness
- Point of contact for supervisory authorities
Reference:
- GDPR: Art. 37-39
- ISO 27001: Annex A.5.2 (Information security roles and responsibilities)
Additional Mandatory Roles for NIS2
Section titled “Additional Mandatory Roles for NIS2”The NIS2 Directive imposes additional requirements on affected organizations (essential and important entities):
Extended Obligations for Executive Management
Section titled “Extended Obligations for Executive Management”New under NIS2:
- ⚠️ Personal liability for violations (Art. 20 Para. 2)
- ✅ Mandatory training on cybersecurity (proof required!)
- ✅ Active oversight of risk management measures
- ✅ Documented responsibility (non-delegable!)
Important: Fines up to 10 million euros or 2% of global annual revenue possible!
Incident Response Team
Section titled “Incident Response Team”Why Mandatory for NIS2:
- Reporting obligations to authorities (early warning: 24h, notification: 72h)
- Coordinated response to security incidents required
Responsibilities:
- Detection and assessment of security incidents
- Immediate containment measures
- Notification to competent authority (CERT/CSIRT)
- Forensics and root cause analysis
- Documentation and lessons learned
Reference:
- NIS2: Art. 23 (Reporting obligations)
- BSI IT-Grundschutz: DER.2.1
Supplier Manager (Supply Chain Security)
Section titled “Supplier Manager (Supply Chain Security)”Why Mandatory for NIS2:
- Art. 21 Para. 2 (e) explicitly requires “security in supply chains”
Responsibilities:
- Identification of critical suppliers
- Risk assessment of suppliers
- Security requirements in contracts
- Monitoring supplier compliance
- Incident management for supplier incidents
Reference:
- NIS2: Art. 21 Para. 2 (e)
- ISO 27001: Annex A.5.19 (Information security in supplier relationships)
Best Practice Roles (Optional, Recommended for Larger Organizations)
Section titled “Best Practice Roles (Optional, Recommended for Larger Organizations)”These roles are not mandatory but strongly recommended, especially for:
- More than 100 employees
- Complex IT landscapes
- Regulated industries (finance, healthcare, energy)
Business Continuity Manager (BCM)
Section titled “Business Continuity Manager (BCM)”Recommended because:
- NIS2 requires “measures to ensure business continuity”
- ISO 27001 Annex A.5.29 (Information security during disruption)
Responsibilities:
- Business Impact Analysis (BIA)
- Creation of Business Continuity Plans (BCP)
- Disaster Recovery Planning (DRP)
- Emergency drills and tests
- Recovery planning after incidents
Typical Time Investment: 20-50% of full-time position
Human Resources (HR Security)
Section titled “Human Resources (HR Security)”Recommended because:
- Employees are the greatest security risk
- On-/offboarding processes critical for security
Responsibilities:
- Security-relevant clauses in employment contracts
- Coordination of background checks (where permissible)
- Onboarding: training, confidentiality agreements
- Offboarding: revoke access rights, return of assets
- Disciplinary measures for security violations
Reference:
- ISO 27001: Annex A.6.1-6.4 (People controls)
- BSI IT-Grundschutz: ORP.2
Compliance Officer
Section titled “Compliance Officer”Recommended because:
- Overlapping requirements (GDPR, NIS2, industry standards)
- Central coordination prevents duplication of effort
Responsibilities:
- Overview of all compliance requirements
- Coordination between DPO, ISO, executive management
- Risk management (cross-functional)
- Audit management and follow-up
- Reporting to executive management
Typical Time Investment: 30-100% of full-time position
Change Advisory Board (CAB)
Section titled “Change Advisory Board (CAB)”Recommended because:
- Changes are a frequent cause of security incidents
- Structured change management reduces risks
Responsibilities:
- Assessment of changes regarding security risks
- Approval or rejection of changes
- Prioritization of changes
- Post-implementation review
Members: IT Management, ISO, affected business units
Reference:
- ISO 27001: Annex A.8.32 (Change management)
- BSI IT-Grundschutz: OPS.1.2.1
Security Awareness Coordinator
Section titled “Security Awareness Coordinator”Recommended because:
- NIS2 requires “training in cybersecurity hygiene”
- Employee awareness is the most cost-effective security measure
Responsibilities:
- Planning and execution of awareness campaigns
- Creation of training materials
- Phishing simulations
- Measuring awareness (e.g., click rates in phishing tests)
- Reporting to ISO and executive management
Typical Time Investment: 10-30% of full-time position
Reference:
- ISO 27001: Annex A.6.3 (Information security awareness, education and training)
- BSI IT-Grundschutz: ORP.3
Internal Audit
Section titled “Internal Audit”Recommended because:
- ISO 27001 requires internal audits (Clause 9.2)
- Independent control increases ISMS quality
Responsibilities:
- Planning and conducting internal ISMS audits
- Identification of nonconformities
- Follow-up on corrective actions
- Preparation for external certification audits
Special Note: Must be independent (cannot audit own work!)
Reference:
- ISO 27001: Clause 9.2 (Internal audit)
- BSI IT-Grundschutz: ORP.5
Summary by Organization Size
Section titled “Summary by Organization Size”Small Organizations (< 50 employees)
Section titled “Small Organizations (< 50 employees)”Minimum:
- ✅ Executive Management
- ✅ ISO (20-30%, possibly external)
- ✅ IT Operations (can be combined with ISO if external control exists)
- ✅ Asset/Process Owner (executive management + department heads)
Additionally for NIS2:
- ✅ Incident Response (can be ISO + IT Operations)
- ✅ Supplier Manager (can be ISO)
Medium-Sized Organizations (50-250 employees)
Section titled “Medium-Sized Organizations (50-250 employees)”In addition to above:
- ✅ Dedicated ISO (50-100%)
- ✅ Clear separation IT Operations ↔ ISO
- ✅ HR Security (part of HR department)
- ✅ BCM Manager (20-50%, can be ISO)
Large Organizations (> 250 employees)
Section titled “Large Organizations (> 250 employees)”In addition to above:
- ✅ CISO (full-time)
- ✅ Security team (multiple people)
- ✅ Compliance Officer (full-time)
- ✅ Dedicated Incident Response Team
- ✅ Internal Audit
- ✅ Security Awareness Coordinator
Avoid Common Mistakes
Section titled “Avoid Common Mistakes”❌ “IT handles it” → Information security is a cross-functional task, not just an IT topic!
❌ “The ISO does everything alone” → ISO coordinates, responsibility lies with asset/process owners
❌ “No time for ISMS tasks” → Plan realistic time budgets (otherwise it won’t work)
❌ “Roles assigned only verbally” → Must be documented in writing!
❌ “For NIS2, appointing an ISO is enough” → No! Executive management has personal training and oversight obligations
Next Steps
Section titled “Next Steps”- Check your NIS2 status → Are you affected?
- Assign roles → Which roles do you need? Who takes them on?
- Document → Create a “Roles & Responsibilities” document
- Train → Especially executive management (mandatory for NIS2!)
- Provide resources → Set realistic time budgets
- Review regularly → At least annually