The Information Security Officer (ISB, Informationssicherheitsbeauftragter) is the role established in German-speaking countries under BSI IT-Grundschutz: it steers and coordinates the security process, supports management with the security policy, coordinates the creation of the security concept, investigates security-relevant incidents and reports directly to top management (BSI Standard 200-2, chapter 4.4). The BSI standard names Chief Information Security Officer (CISO) and Information Security Manager (ISM) as common alternative titles for the same role; in international usage, CISO moreover often denotes a strategic leadership role with responsibility for security strategy, budget and organisation, frequently with its own team and a position directly below executive management. In practice the two profiles overlap heavily, and in smaller organisations one person often covers both perspectives. What matters is less the title than the clear assignment of tasks, authority and reporting lines.
vCISO and External Information Security Officer
What distinguishes a CISO from an ISB, what requirements ISO 27001 and NIS2 place on assigning the role – and when filling it externally as a vCISO or vISB makes sense.
Information security needs a clearly designated role equipped with real authority: BSI Standard 200-2 provides for the appointment of an Information Security Officer (ISB), ISO/IEC 27001 requires in Clause 5.3 that responsibilities be assigned and communicated, and NIS2 explicitly anchors responsibility for security with the management bodies. Not every organisation can or wants to fill this role internally on a full-time basis – skills shortages, insufficient workload in smaller organisations and role conflicts with IT often argue for an external arrangement as a vCISO or virtual ISB. This article puts the role profiles into context, describes the task catalogue and the common operating models – and shows where the limits of delegation lie.
The Essentials at a Glance
Six topic blocks — tap to expand.
Operating models compared
Three basic models have become established in practice – regardless of the model, a written appointment, a role and interface description, deputisation arrangements and confidentiality agreements are part of a clean implementation.
- The external vCISO/vISB holds the role permanently with a fixed monthly quota of hours or days.
- Predictable for recurring tasks such as risk management, reporting and awareness.
- Complemented by contractually defined response times for incidents.
- Bridges a vacancy with a high level of presence.
- Clearly time-limited: ends with the position being refilled or handed over.
- Supports an initiative with a defined goal, such as building an ISMS to certification readiness.
- Hybrid variants combine the external role with coaching an internal junior until handover.
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
BSI-Standard 200-2: IT-Grundschutz-Methodik
Chapter 4.4 describes the appointment, tasks and requirements profile of the Information Security Officer as well as the role's organisational anchoring with a direct reporting line to management.
Online-Kurs IT-Grundschutz, Lerneinheit 2.4: Der Informationssicherheitsbeauftragte
BSI online course (accessed 07/2026) with the ISB's task catalogue, the warning about role conflicts when the role is integrated into IT, and guidance on combining it with the DPO function.
ISO/IEC 27001:2022 – Information security, cybersecurity and privacy protection – Information security management systems – Requirements
Clause 5.3 requires responsibilities for security-relevant roles to be assigned and communicated, in particular for ISMS conformity and performance reporting to top management.
Richtlinie (EU) 2022/2555 (NIS2)
Art. 20 (governance) obliges the management bodies to approve and oversee the risk management measures under Art. 21 and to attend regular training, and establishes their liability for infringements.
Gesetz zur Umsetzung der NIS-2-Richtlinie und zur Regelung wesentlicher Grundzüge des Informationssicherheitsmanagements in der Bundesverwaltung (neues BSIG)
German NIS2 transposition, promulgated on 5 December 2025 and in force since 6 December 2025; § 38 BSIG governs the management's implementation, oversight and training obligations as well as their internal liability under corporate law.
Related Services
Filling the role – internally or externally?
If you are assessing whether a vCISO or external ISB is the right path for your organisation, we are happy to walk through requirements and operating models with you in a no-obligation initial consultation.