Skip to content

ISMS Responsibilities

A functioning Information Security Management System (ISMS) requires clearly defined roles and responsibilities. The requirements differ depending on the applicable standard:

  • ISO 27001 and BSI IT-Grundschutz: Basic ISMS roles
  • NIS2 Directive: Additional obligations, especially for executive management

Mandatory Roles According to ISO 27001 & BSI IT-Grundschutz

Section titled “Mandatory Roles According to ISO 27001 & BSI IT-Grundschutz”

These roles are mandatory for every ISMS:

1. Executive Management / Senior Leadership

Section titled “1. Executive Management / Senior Leadership”

Responsibilities:

  • Overall responsibility for information security
  • Approval of the Information Security Policy
  • Provision of resources (budget, personnel, time)
  • Appointment of the Information Security Officer
  • Annual management review

Reference:

  • ISO 27001: Clause 5.1 (Leadership and commitment)
  • BSI IT-Grundschutz: ORP.1.A1

Responsibilities:

  • Central coordination of the ISMS
  • Advisory to executive management on security matters
  • Creation and maintenance of security documentation
  • Monitoring implementation of security measures
  • Point of contact for all security questions

Reference:

  • ISO 27001: Clause 5.3
  • BSI IT-Grundschutz: ORP.1.A15

Typical Time Investment: 20-50% of full-time position (depending on organization size)


Responsibilities:

  • Technical implementation of security measures
  • Configuration and operation of IT systems
  • Patch management and updates
  • Incident response (technical level)
  • Backup and recovery

Reference:

  • ISO 27001: Clause 8 (Operation)
  • BSI IT-Grundschutz: OPS.1.1.2

Responsibilities:

  • Responsibility for specific information assets
  • Classification of protection requirements
  • Approval of access rights
  • Monitoring proper use

Examples: Head of Finance (owner of financial data), Production Manager (owner of control systems)

Reference:

  • ISO 27001: Annex A.5.9 (Inventory of information and other associated assets)
  • BSI IT-Grundschutz: ORP.4

Responsibilities:

  • Responsibility for the security of a business process
  • Integration of security requirements into the process
  • Business Impact Analysis (BIA) for the process
  • Approval of process-specific security measures

Examples: Sales Manager (owner of sales process), Production Manager (owner of production process)

Reference:

  • ISO 27001: Clause 6.1.2 (Information security risk assessment)
  • BSI IT-Grundschutz: ORP.1

Special Note: Mandatory for public authorities and certain private organizations under GDPR Art. 37

Responsibilities:

  • Monitoring GDPR compliance
  • Advisory on data protection matters
  • Training and awareness
  • Point of contact for supervisory authorities

Reference:

  • GDPR: Art. 37-39
  • ISO 27001: Annex A.5.2 (Information security roles and responsibilities)

The NIS2 Directive imposes additional requirements on affected organizations (essential and important entities):

Extended Obligations for Executive Management

Section titled “Extended Obligations for Executive Management”

New under NIS2:

  • ⚠️ Personal liability for violations (Art. 20 Para. 2)
  • Mandatory training on cybersecurity (proof required!)
  • Active oversight of risk management measures
  • Documented responsibility (non-delegable!)

Important: Fines up to 10 million euros or 2% of global annual revenue possible!


Why Mandatory for NIS2:

  • Reporting obligations to authorities (early warning: 24h, notification: 72h)
  • Coordinated response to security incidents required

Responsibilities:

  • Detection and assessment of security incidents
  • Immediate containment measures
  • Notification to competent authority (CERT/CSIRT)
  • Forensics and root cause analysis
  • Documentation and lessons learned

Reference:

  • NIS2: Art. 23 (Reporting obligations)
  • BSI IT-Grundschutz: DER.2.1

Why Mandatory for NIS2:

  • Art. 21 Para. 2 (e) explicitly requires “security in supply chains”

Responsibilities:

  • Identification of critical suppliers
  • Risk assessment of suppliers
  • Security requirements in contracts
  • Monitoring supplier compliance
  • Incident management for supplier incidents

Reference:

  • NIS2: Art. 21 Para. 2 (e)
  • ISO 27001: Annex A.5.19 (Information security in supplier relationships)

Section titled “Best Practice Roles (Optional, Recommended for Larger Organizations)”

These roles are not mandatory but strongly recommended, especially for:

  • More than 100 employees
  • Complex IT landscapes
  • Regulated industries (finance, healthcare, energy)

Recommended because:

  • NIS2 requires “measures to ensure business continuity”
  • ISO 27001 Annex A.5.29 (Information security during disruption)

Responsibilities:

  • Business Impact Analysis (BIA)
  • Creation of Business Continuity Plans (BCP)
  • Disaster Recovery Planning (DRP)
  • Emergency drills and tests
  • Recovery planning after incidents

Typical Time Investment: 20-50% of full-time position


Recommended because:

  • Employees are the greatest security risk
  • On-/offboarding processes critical for security

Responsibilities:

  • Security-relevant clauses in employment contracts
  • Coordination of background checks (where permissible)
  • Onboarding: training, confidentiality agreements
  • Offboarding: revoke access rights, return of assets
  • Disciplinary measures for security violations

Reference:

  • ISO 27001: Annex A.6.1-6.4 (People controls)
  • BSI IT-Grundschutz: ORP.2

Recommended because:

  • Overlapping requirements (GDPR, NIS2, industry standards)
  • Central coordination prevents duplication of effort

Responsibilities:

  • Overview of all compliance requirements
  • Coordination between DPO, ISO, executive management
  • Risk management (cross-functional)
  • Audit management and follow-up
  • Reporting to executive management

Typical Time Investment: 30-100% of full-time position


Recommended because:

  • Changes are a frequent cause of security incidents
  • Structured change management reduces risks

Responsibilities:

  • Assessment of changes regarding security risks
  • Approval or rejection of changes
  • Prioritization of changes
  • Post-implementation review

Members: IT Management, ISO, affected business units

Reference:

  • ISO 27001: Annex A.8.32 (Change management)
  • BSI IT-Grundschutz: OPS.1.2.1

Recommended because:

  • NIS2 requires “training in cybersecurity hygiene”
  • Employee awareness is the most cost-effective security measure

Responsibilities:

  • Planning and execution of awareness campaigns
  • Creation of training materials
  • Phishing simulations
  • Measuring awareness (e.g., click rates in phishing tests)
  • Reporting to ISO and executive management

Typical Time Investment: 10-30% of full-time position

Reference:

  • ISO 27001: Annex A.6.3 (Information security awareness, education and training)
  • BSI IT-Grundschutz: ORP.3

Recommended because:

  • ISO 27001 requires internal audits (Clause 9.2)
  • Independent control increases ISMS quality

Responsibilities:

  • Planning and conducting internal ISMS audits
  • Identification of nonconformities
  • Follow-up on corrective actions
  • Preparation for external certification audits

Special Note: Must be independent (cannot audit own work!)

Reference:

  • ISO 27001: Clause 9.2 (Internal audit)
  • BSI IT-Grundschutz: ORP.5

Minimum:

  • ✅ Executive Management
  • ✅ ISO (20-30%, possibly external)
  • ✅ IT Operations (can be combined with ISO if external control exists)
  • ✅ Asset/Process Owner (executive management + department heads)

Additionally for NIS2:

  • ✅ Incident Response (can be ISO + IT Operations)
  • ✅ Supplier Manager (can be ISO)

Medium-Sized Organizations (50-250 employees)

Section titled “Medium-Sized Organizations (50-250 employees)”

In addition to above:

  • ✅ Dedicated ISO (50-100%)
  • ✅ Clear separation IT Operations ↔ ISO
  • ✅ HR Security (part of HR department)
  • ✅ BCM Manager (20-50%, can be ISO)

In addition to above:

  • ✅ CISO (full-time)
  • ✅ Security team (multiple people)
  • ✅ Compliance Officer (full-time)
  • ✅ Dedicated Incident Response Team
  • ✅ Internal Audit
  • ✅ Security Awareness Coordinator

“IT handles it” → Information security is a cross-functional task, not just an IT topic!

“The ISO does everything alone” → ISO coordinates, responsibility lies with asset/process owners

“No time for ISMS tasks” → Plan realistic time budgets (otherwise it won’t work)

“Roles assigned only verbally” → Must be documented in writing!

“For NIS2, appointing an ISO is enough” → No! Executive management has personal training and oversight obligations


  1. Check your NIS2 status → Are you affected?
  2. Assign roles → Which roles do you need? Who takes them on?
  3. Document → Create a “Roles & Responsibilities” document
  4. Train → Especially executive management (mandatory for NIS2!)
  5. Provide resources → Set realistic time budgets
  6. Review regularly → At least annually