01Role profiles: CISO and ISB compared
The Information Security Officer (ISB, Informationssicherheitsbeauftragter) is the role established in German-speaking countries under BSI IT-Grundschutz: it steers and coordinates the security process, supports management with the security policy, coordinates the creation of the security concept, investigates security-relevant incidents and reports directly to top management (BSI Standard 200-2, chapter 4.4). The BSI standard names Chief Information Security Officer (CISO) and Information Security Manager (ISM) as common alternative titles for the same role; in international usage, CISO moreover often denotes a strategic leadership role with responsibility for security strategy, budget and organisation, frequently with its own team and a position directly below executive management. In practice the two profiles overlap heavily, and in smaller organisations one person often covers both perspectives. What matters is less the title than the clear assignment of tasks, authority and reporting lines.
02Requirements from ISO 27001 Clause 5.3 and NIS2 Art. 20
ISO/IEC 27001:2022 requires in Clause 5.3 that top management assign and communicate responsibilities and authorities for security-relevant roles – in particular for the ISMS's conformity with the standard and for reporting on its performance to top management; Annex A control 5.2 additionally calls for defined security roles. The standard does not prescribe a specific title such as “CISO”. NIS2 (Directive (EU) 2022/2555) obliges, in Art. 20, the management bodies of essential and important entities to approve the risk management measures under Art. 21 and oversee their implementation; they can be held liable for infringements and must attend training. In Germany, the new BSIG (NIS2 Implementation Act), in force since 6 December 2025, transposes these obligations: § 38 BSIG obliges the management of particularly important and important entities to implement the risk management measures, monitor their implementation and attend training on a regular basis.
03Task catalogue of an ISB/CISO
At the core of the role is steering the entire security process: contributing to the security strategy and policy, building and maintaining the body of policies, and coordinating the security concept. Added to this are risk management (methodology, risk analyses, action plans and their follow-up), initiating and coordinating awareness and training measures, and investigating security-relevant incidents. Towards management, the role owns management reporting – status reports, key figures and input to the management review under ISO/IEC 27001 Clause 9.3. It also covers providing security support for projects and procurement as well as preparing internal and external audits.
04When an external appointment makes sense
BSI Standard 200-2 explicitly provides in chapter 4.11 for having key roles such as the ISB performed by qualified external specialists if they cannot be filled internally – especially in small companies and public authorities, drawing on an external ISB can be expedient. Common triggers are a lack of qualified staff, a role that does not sustain a full-time position, or a vacancy that needs to be bridged at short notice. The required independence can also be an argument: the BSI explicitly warns of role conflicts when the ISB is integrated into the IT department and cannot perform its oversight duties free from influence; combining the role with that of the data protection officer is, in the BSI's view, not uncritical and only acceptable where the interfaces between both duties are clearly defined. External role holders also bring experience from many organisations and certification procedures. The prerequisite is that an internal point of contact is designated and the external role holder is given access to committees, information and decision-making channels – without that integration, the role remains ineffective.
05Operating models: retainer, interim, project-based
In practice, three basic models have become established. In the retainer model, the external vCISO/vISB holds the role permanently with a fixed monthly quota of hours or days – predictable for recurring tasks such as risk management, reporting and awareness, complemented by contractually defined response times for incidents. The interim model bridges a vacancy with a high level of presence, is clearly time-limited and ends with the position being refilled or handed over. Project-based models support an initiative with a defined goal, such as building an ISMS to certification readiness; hybrid variants combine the external role with coaching an internal junior until handover. Regardless of the model, a written appointment, a description of the role and its interfaces, deputisation arrangements and confidentiality agreements are part of a clean implementation.
06Limits: overall responsibility stays with executive management
Neither internally nor externally can responsibility for information security be handed off entirely: under BSI Standard 200-2, overall responsibility remains with the top management level – it decides how risks are handled and provides the resources, even when it delegates operational tasks. NIS2 Art. 20 and § 38 BSIG explicitly address the approval or implementation and oversight of the risk management measures, as well as training participation, to the management bodies themselves; § 38 Abs. 2 BSIG attaches to this an internal liability of managing directors under the rules of corporate law. An external vCISO/vISB advises, steers the security process and prepares decisions – risk acceptance, approval of the policy and budget decisions are taken by executive management itself. Credible operating models make this division of labour explicit, for instance through defined escalation and reporting channels and a documented decision paper for each risk.