77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
Difference between ISB and CISO explained: role, duties, reporting line
IT Security & NIS-2

Difference between ISB and CISO explained: role, duties, reporting line

1 September 202613 min readBy Lena Vogt
CIVAC

ISB and CISO are often used interchangeably, but they are different. The ISB is the formal German representative role according to BSIG and KRITIS, the CISO is the operational management function. This guide shows the dividing line, the interfaces and the document-proof setup path.

The information security officer (ISB) has come into focus since October 18, 2024 with the NIS 2 Directive (EU) 2022/2555 and the German NIS2UmsuCG. Around 29,500 companies in Germany are affected and must organise a named security responsibility. At the same time, every medium and large company has long had a Chief Information Security Officer (CISO), often years before NIS-2.

This article clearly explains the dividing line between ISB and CISO: legal anchoring, catalogue of tasks, reporting line, qualifications and interfaces to DSB, CO and management. You will find out whether you need both roles, when a person can manage both and how CIVAC, as a compliance platform and officer-as-a-service, maps the setup in a document-proof manner.

Key Takeaways

  • The ISB is a formally appointed representative role according to BSIG, BSI-Grundschutz and KRITIS Ordinance, the CISO is the operational line responsibility for information security.
  • One person may hold both functions in medium-sized companies, provided there are no conflicts of interest and the appointment document is clearly documented.
  • CIVAC delivers both models: licence the workspace for your internal ISB and CISO or have our officers appointed it.

ISB: The formal representative role in German law

The ISB is a German representative role with roots in the BSI-Grundschutz and is explicitly anchored in the KRITIS regulation and the BSIG. The role has been established in public administration for years and, with the German NIS2UmsuCG, is now also relevant for the approximately 29,500 NIS 2 affected companies in the private sector.

The ISB is not literally required to be appointed in every law, but is in fact indispensable for fulfilling the NIS 2 obligations according to Section 30 BSIG (new). The tasks include the maintenance of the information security management system (ISMS), the risk analysis, the business process assessment, the reporting line to management and the interface to the BSI.

The appointment certificate is the formal act. It contains tasks, authorities, reporting line and order period. Without an appointment certificate, the role in the audit can hardly be proven. The appointment certificate, signed, filed, verifiable applies here in full force.

The qualification is based on BSI standard 200-1 and 200-2. The usual requirements are a computer science degree, several years of professional experience, BSI-Grundschutz practitioner certificate and ISO/IEC 27001 lead implementer or lead auditor.

The reporting line goes directly to the management. This is NIS-2 compliant and corresponds to the expectations of the BSI. A reporting line through the CIO or CISO guts the role and is vulnerable to scrutiny. More at civac.de/roles/informationssicherheitspflichter.

CISO: The operational management function

The CISO is a line function without a direct legal anchor in German law. The role comes from the Anglo-Saxon corporate governance tradition and describes the operational responsibility for a company's information security.

The CISO typically leads a team of security engineers, SOC analysts and architects. He is responsible for the security budget, roadmap, vendor selection and crisis response. Depending on the organisation, the reporting line goes to the CIO, the CTO or the CFO, and in an increasing number of companies also directly to the CEO.

In the regulated area, such as banks according to Section 25a KWG, the CISO has indirect legal significance via the BaFin BAIT requirements. The BAIT requires a clearly identified information security function with appropriate resources and escalation rights.

The qualification typically includes CISSP, CISM, CISO certificates and several years of line management experience. Unlike the ISB, the qualification expectations are less formal, but in practice they are comparably high.

The key difference to the ISB lies in the role architecture. The CISO leads operationally, the ISB monitors and reports independently. In large organisations, both roles are filled separately, in medium-sized companies often in one person, with a clear separation in the appointment certificate.

For the operational interface to the DPO see external data protection officer.

Intersection: Where ISB and CISO do the same thing

Around 60 percent of the activities overlap. Both roles take care of risk analysis, security guidelines, awareness training, incident management and the ISMS according to ISO/IEC 27001:2022 with its 93 controls.

Both roles report incidents to management. Both roles coordinate with the DPO in the event of data breaches in accordance with Article 33 GDPR with the 72-hour deadline. Both roles carry out the supplier evaluation with regard to security.

In the NIS 2 context, both roles are addressees for the management's training obligation in accordance with Section 38 BSIG (new). Both have to operationally carry out the 24-hour early warning and the 72-hour follow-up report to the BSI.

Both roles maintain the audit material for external audits. Both roles coordinate with the CO on the compliance reporting line. Both roles take the lead in exercises such as tabletop exercises and penetration tests.

The operational overlap is so great that the separation of roles immediately becomes blurred without a clear appointment certificate and specifications. In practice, this leads to duplication of work, gaps or conflicts in the crisis.

CIVAC maps both roles in the same workspace, with separate role rights and a common audit trail. The 490 ready-to-use audit templates are cut so that the intersection is processed efficiently, but the dividing lines remain visible.

Dividing line: Where ISB and CISO work differently

Three differences are structural. First, independence. In the representative function, the ISB is organizationally independent, has the right to speak to the management and may not be bound by instructions in its recommendations.

The CISO, on the other hand, has a line function. He receives instructions, maintains a budget, negotiates with suppliers and bears the operational consequences of his decisions. The two poles cannot be combined in any way.

Secondly, the reporting line. The ISB reports directly to management, often in writing and quarterly. Depending on the organisation, the CISO reports to the CIO or the CFO and only in exceptional cases directly to the CEO. In the case of NIS 2-relevant incidents, the reporting path to management must always be guaranteed.

Third, the focus of responsibility. The ISB focuses on compliance, audit robustness and external reporting obligations, for example to the BSI. The CISO focuses on operational effectiveness, responsiveness and security architecture. Both foci need each other, but they are not identical.

The order in practice follows from this. In the large corporation with more than 5,000 employees, both roles are filled separately. In medium-sized companies with 250 to 1,500 employees, one person often manages both functions, often with external ISB support. In smaller medium-sized companies, an external ISB takes over the function completely.

Others run compliance like a filing cabinet. We run it like software. The CIVAC Workspace makes the dividing line operationally visible.

NIS-2 and KRITIS: Legal anchoring in 2026

With the NIS2UmsuCG, the BSIG (new) anchors the expectation of a named information security function in around 29,500 German companies. Essential facilities in accordance with Section 28 BSIG (new) and important facilities must meet the security requirements in accordance with Section 30 BSIG and comply with the reporting obligations in accordance with Section 32 BSIG.

The reporting paths are clearly timed. An early warning must be sent to the BSI within 24 hours of becoming aware of it. The follow-up message will follow within 72 hours. The final report within a month. The deadline expires as soon as we become aware of it, this is codified several times in the BSIG.

The fines are high. For important facilities up to 10 million euros or 2 percent of group sales, for important facilities up to 7 million euros or 1.4 percent of group sales. The management is also personally liable in accordance with Section 38 BSIG.

The KRITIS Ordinance supplements the obligation for operators of critical systems to take additional safety measures, regular evidence and a contact point in accordance with Section 32 BSIG. The ISB is usually the named contact here.

The interface to the BSI requires a trained and continuously accessible function. A pure CISO function without an ISB profile is often not enough in the audit because the representative role and the right to present are not clearly documented.

CIVAC maps all NIS 2 reporting paths in the workspace, with an escalation clock, templates for the three reports and an audit trail. More in the NIS-2 overview.

One person, two roles? When that works and when it doesn't

In medium-sized companies, double staffing is common and permitted. The BSI expressly allows the personnel union as long as conflicts of interest are excluded and the roles are clearly documented separately in the appointment certificate.

When it is possible: with clearly separated catalogues of tasks, with a documented reporting line to the management in the ISB function, with sufficient time for both roles and with a formal separation of the audit tracks.

When it is not possible: if the CISO, as the budget manager, would have to audit his own decisions as an ISB when he is a supplier which he would then have to check independently as an ISB if the personal union blocks escalation in the crisis.

The solution in medium-sized companies is usually the hybrid form. An internal CISO takes on line responsibility, an external ISB takes on the independent representative role. The audit trail is clean, escalation works even if the CISO himself is part of the incident.

CIVAC offers this hybrid form as Officer-as-a-Service. The external ISB is appointed with an appointment certificate, specifications and reporting line to the management, the internal CISO remains in the line management. The auditor calls, the evidence is ready.

Licence the workspace for your internal CISO or have our representatives appointed, depending on your maturity and risk profile.

Interfaces to DSB, CO, data protection supervision and BSI

The ISB and the CISO work in a network of interfaces. The most important is the DSB. In the case of data breaches in accordance with Article 33 GDPR with a 72-hour deadline, the DPO coordinates the report to the data protection supervisory authority, the ISB and the CISO provide the technical facts.

The second interface is the Compliance Officer. In the case of security incidents related to compliance, such as data theft with subsequent suspicion of insider involvement, the CO coordinates the legal assessment and possible reporting.

The third interface is the data protection supervision of the federal states. Here the DSB is the formal contact, but the ISB provides the technical assessment. In the case of NIS 2 incidents, the BSI as the higher federal authority is also addressed.

The fourth interface is the CERT-Bund and the industry-specific CERTs. These coordinate the response to systemic incidents and provide early warnings. The ISB maintains the channel, the CISO implements the measures operationally.

The fifth interface is the management. Every escalation ends here. The ISB's appointment certificate must clearly regulate the right of presentation, without having to go through the CIO or CFO. This is NIS-2 compliant and can be proven in the audit.

CIVAC maps all five interfaces in the workspace, with escalation paths, reporting forms and audit trail. The integration with the Compliance Officer is native.

Setup in medium-sized businesses: Order in 14 days

A document-proof ISB and CISO setup in medium-sized companies runs in five phases. Phase one, days 1 to 3, scoping. Inclusion of the NIS 2 impact, the existing security functions, the existing appointment certificates and the ISMS maturity.

Phase two, days 4 to 6, contract and appointment certificate. Creation of the appointment certificate with specifications, reporting line and escalation mechanics. If external, also the order processing contract according to Article 28 GDPR and the financial loss liability.

Phase three, days 7 to 10, ISMS initialization. Workspace setup, configuration of the 93 controls according to ISO/IEC 27001:2022, setup of the 490 audit templates, anchoring of the NIS-2 24/72 reporting paths.

Phase four, days 11 to 12, training. Training of management in accordance with Section 38 BSIG (new), training of the internal CISO or security team, awareness plan for the workforce.

Phase five, days 13 to 14, go-live. Activation of escalation paths, reporting rhythm, supplier evaluation. First quarterly meeting with management is being planned.

The CIVAC SLA of 2 working days for the appointment certificate shortens phase two significantly. Classic setups take 2 to 6 weeks, the CIVAC setup takes 14 days. Audit-proof, documented, § 30-BSIG-proof. Turn reading into an assignment.

Turn reading into a mandate.: CIVAC for ISB and CISO

You have two ways to build a document-proof information security function with CIVAC. Both end with the appointment certificate, signed, filed, verifiable in your file and with active 24/72 reporting paths to the BSI.

Path one, the workspace. Your internal ISB and your CISO work together on the CIVAC platform, with separate role rights, common audit trail, 93 controls according to ISO/IEC 27001:2022 and 490 ready-to-use audit templates. Licence the workspace for your internal officers.

Way two, Officer-as-a-Service. CIVAC provides an external ISB with an appointment certificate, specifications and reporting line to the management. The internal CISO remains line manager. Or have our officers appointed it. Both models share EU data residency and NIS-2 reporting paths.

Others run compliance like a filing cabinet. We run it like software. The CIVAC SLA is 2 working days from the contract signing to the appointment certificate being issued. Classic providers need 2 to 6 weeks.

You receive the audit templates, the specifications, the reporting line to management, the escalation mechanism with 24-hour early warning and 72-hour follow-up notification and the integration with DSB, CO and data protection supervision. The auditor calls, the evidence is ready.

Turn reading into a mandate.: Write to info@civac.de with industry, number of employees and NIS 2 classification. You will receive a suitable list of services and a draft appointment certificate within 48 hours. Alternatively, use the contact form on civac.de/faq.

FAQ

Is the ISB legally binding?

There is no literal obligation to order in the BSIG (new), but the fulfilment of the obligations according to Section 30 BSIG and the reporting obligations according to Section 32 BSIG can hardly be documented without an ISB role. The order is therefore effectively indispensable for the approximately 29,500 companies in Germany affected by NIS 2.

Can a person be ISB and CISO at the same time?

Yes, personal union is permitted in medium-sized companies if there are no conflicts of interest and the roles are clearly separated in the appointment certificate. When there is budget responsibility and a simultaneous audit obligation, a conflict usually arises that makes an external ISB useful.

What qualifications does an ISB have to have?

Common market requirements include a computer science or comparable degree, several years of professional experience, BSI-Grundschutz practitioner or BSI-Grundschutz consultant, ISO/IEC 27001 Lead Implementer or Lead Auditor. CIVAC provides officers with this qualification and financial loss liability insurance.

What happens in the event of a security incident in an NIS 2 affected company?

An early warning is sent to the BSI within 24 hours of becoming aware of it, the follow-up report within 72 hours, and the final report within a month. The ISB coordinates the reports, the CISO is responsible for the operational response. CIVAC has the escalation clock and templates ready.

Can the CISO report directly to management instead of the CIO?

Yes, this is actually recommended and increasingly corresponds to the current state of practice. For the ISB role, the direct reporting line to management must be anchored in the appointment certificate. A reporting line through the CIO guts the ISB function and is vulnerable in the audit.

How quickly can CIVAC order an external ISB?

The CIVAC SLA is 2 working days from the contract signing to the appointment certificate being issued. Classic providers need 2 to 6 weeks. The complete onboarding including ISMS initialization and first quarterly report is completed within 14 days.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles