77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
Information security officer: role, duties and appointment in medium-sized companies
IT Security & NIS-2

Information security officer: role, duties and appointment in medium-sized companies

28 June 202612 min readBy Lena Vogt
CIVAC

The information security officer (ISB) has operational responsibility for the ISMS according to ISO/IEC 27001:2022. The article explains tasks, the appointment certificate, the distinction between CISO and CIO as well as the obligations under NIS-2, KRITIS umbrella law and DORA.

The information security officer has been the central operational role for information security in the company since the publication of ISO/IEC 27001:2022 in October 2022 and the entry into force of the NIS 2 implementation law at the European level in 2024. According to estimates by the Federal Office for Information Security, around 29,500 companies in Germany are directly covered by the NIS 2 regime, including manufacturers, providers of digital services, energy and healthcare providers as well as significant parts of the industrial supply chain. At the same time, ISO/IEC 27001:2022 with its 93 controls, the KRITIS umbrella law, DORA for financial service providers, the TISAX standard for the automotive industry and the BSI C5 catalogue require clear responsibility for information security. This responsibility is borne by the information security officer, abbreviated as ISB. Anyone who does not order the function or only formally orders it will lose out in the audit, in the incident and in the supplier evaluation.

This article explains what the ISB does specifically, how it differentiates itself from the Chief Information Security Officer and the IT manager, when its order becomes binding and what trace of evidence supervisory authorities and auditors expect. As a compliance platform and officer-as-a-service, CIVAC supports information security officers in industry, energy supply, financial services, healthcare and upper medium-sized businesses with a configurable workspace, 490 audit templates, 93 prepared controls and the NIS-2-specific 24- and 72-hour reporting path. Licence the workspace for your internal representatives or have our representatives order it. The appointment certificate, signed, filed, verifiable. You will find out where the most common gaps lie in German medium-sized companies and how they can be closed.

Key Takeaways

  • The information security officer is a written-appointed role with operational responsibility for the ISMS, clearly separated from CISO, CIO and IT management.
  • Under NIS-2, ISO/IEC 27001:2022, DORA and in the KRITIS environment, the function becomes mandatory in practice and the appointment certificate becomes part of the mandatory audit documents.
  • A reliable reporting line to the management with documented reports protects the personal liability of the management in accordance with Section 130 OWiG and Section 38 NIS2UmsuCG.

What an information security officer is specifically responsible for

The information security officer is operationally responsible for the organisation's information security. He designs, operates and monitors the information security management system according to ISO/IEC 27001:2022, coordinates the 93 controls from Appendix A and maintains the associated documentation. He develops security guidelines, checks their implementation in the departments and reports to the management. He is the first point of contact for internal and external auditors, for supervisory authorities such as the Federal Office for Information Security and, in collaboration with the data protection officer, for IT-related data protection breaches. In companies affected by NIS 2, he also coordinates the reporting path with 24-hour early warning and 72-hour follow-up notification to the responsible authority, which decides on personal liability issues in the event of a dispute.

The task list typically includes ten areas. Firstly, ISMS governance with guidelines and scope. Secondly, risk assessment with threat modelling and risk registers. Thirdly, the technical and organisational measures with assignment to controls. Fourth, identity and authorisation management. Fifth, patch and vulnerability management. Sixth, incident management with an escalation plan. Seventh, supplier security and vendor risk management. Eighth, the awareness programs and mandatory training. Ninth, the business continuity planning and the emergency manual. Tenth, the regular internal audits and management review in accordance with clause 9.3.

These tasks are operational and clearly distinguish the ISB from strategically focused roles such as the CISO. CIVAC structures the task list at civac.de/roles/informationssicherheitshelfer according to ISO/IEC 27001:2022 with the 93 controls as the central backbone. Each task is provided with a template, person responsible, deadline and verification step. The ISB sees in the dashboard where the next measure is due, who will take it on and what audit evidence will be generated. This structural management replaces the usual Excel patchwork and can be checked immediately in the audit without anyone having to search through file shares.

Demarcation: ISB, CISO, CIO and IT security officer

The terms information security officer, IT security officer, chief information security officer and chief information officer are often mixed in practice, but describe different roles. The ISB is the established name in Germany for operational responsibility in the ISMS and is based on the BSI-IT-Grundschutz and ISO/IEC 27001:2022. The IT security officer is often synonymous, but with a focus on technical IT security and less on the overarching information security, which also includes organisational, personnel and physical aspects.

The CISO is the internationally used name for a strategic role that reports directly to the management in larger companies and, in addition to information security, is also responsible for topics such as cyber risk management, compliance and crisis management. In medium-sized companies, ISB and CISO tasks are often combined in one role, while in corporations the CISO works strategically and one or more ISBs work operationally in the group companies. The CIO leads IT as a whole with a focus on architecture, procurement and operations and is not the security officer as defined by ISO/IEC 27001:2022. A CIO/ISB personal union is problematic because of the conflict of interest in audits.

A clear functional description is therefore recommended in the appointment. From a disciplinary point of view, the ISB is usually not subordinate to IT, but is linked to the management or the risk and compliance board. A staff union between ISB and IT managers is possible, but must be explained regularly in audits because it creates conflicts of interest. CIVAC provides the typical role matrices for medium-sized constellations under Compliance Officer in which ISB, data protection and compliance work together at clearly defined interfaces. The appointment certificate documents the organisational assignment in a binding manner and makes the separation of roles transparent for auditors.

When the order becomes binding: NIS-2, KRITIS, DORA, TISAX

There is not an explicit legal obligation to appoint an information security officer in all industries in Germany, but in practice it is enforced by a number of regulations. The NIS 2 Implementation Act, which will come into full force in spring 2026, requires around 29,500 affected companies to have security management with designated responsibility. The specification takes place via Section 30 NIS2UmsuCG with risk management measures, the implementation of which must be tied to one person, and via Section 32 NIS2UmsuCG with training obligations of the management bodies. Fines range up to 10 million euros or 2 percent of group sales for important institutions, and up to 7 million euros or 1.4 percent for important institutions.

In the KRITIS environment according to the BSI law and the KRITIS umbrella law, the function is mandatory, as is the case with TISAX for the automotive industry, with DORA for financial service providers, with C5 for cloud providers in the official environment and with ISO/IEC 27001:2022 in everyone Certification level. The ISO standard expressly requires assigned responsibility for the ISMS in clause 5.3 and the demonstrable competence of the responsible person in clause 7.2. These requirements are regularly checked in audits based on the appointment certificate. Without a documented order, certification will be rejected in Stage 1.

In unregulated industries, the obligation often arises indirectly from customer requirements, supplier audits and insurance conditions. Since around 2024, cyber insurance companies have required the appointment of a responsible information security officer as a minimum requirement for insurance coverage in many policies. CIVAC documents the order in the workspace with an appointment certificate, catalogue of tasks, reporting line and representation regulations. Audit-proof, documented, § 38 NIS2UmsuCG-proof. As soon as the company's constellation changes, for example due to an acquisition or entry into a KRITIS segment, the role configuration in the workspace is adjusted without the historical document trail being lost.

Internal order, external ISB or hybrid model

The role of information security officer can be filled internally, externally or in a hybrid model. An internal order is the norm in larger companies with their own IT security department. It has the advantage of immediate accessibility, organisational knowledge and anchoring in the line. The high personnel requirement is disadvantageous because an ISB role in regulated industries often requires 1.0 full-time positions or more and also requires specialist knowledge in law, auditing and technology. Vacancies quickly arise due to parental leave, changes or illness and create audit risks.

The external appointment delegates the function to an external representative who takes on the role as a service. The advantages are reliable availability even when there are vacancies, formal protection against conflicts of interest, lower fixed costs and access to specialist knowledge that is not available in individual companies. The disadvantage is the lower depth of internal knowledge. In the hybrid model, an external ISB takes on the formal role, reporting line and audit representation, while internal employees carry out the operational implementation in the specialist departments. This model is increasingly becoming standard in medium-sized businesses.

CIVAC offers both models in one platform. Licence the workspace for your internal representatives or have our representatives order it. It is possible to switch between models without breaking the receipt track. If the model changes from external to internal, for example, appointment certificates, risk registers, reports and training certificates remain available and are transferred to the new functionary. The CIVAC SLA of 2 working days instead of the usual 2 to 6 weeks closes the response gap that arises in classic consulting mandates when unexpected audits or incidents occur. Audit-proof, documented, § 30 NIS2UmsuCG-proof.

The appointment certificate: mandatory components and pitfalls

The appointment certificate is the formally binding document with which the function of the information security officer is transferred. It is not regulated word-for-word in any law, but has established itself as a mandatory component in audit practice. A reliable appointment certificate contains eight elements. Firstly, the full name, function and organisational unit of the appointed person. Secondly, the effective date and the time limit, if one is provided. Third, the assigned tasks in a clear catalogue with reference to ISO/IEC 27001:2022 and relevant laws. Fourth, the organisational connection with reporting line to management.

Fifth, the resources made available, including access rights to systems, budget and external advice. Sixth, the replacement policy for absences. Seventh, the right to further education and the right to relevant training. Eighth, the signature of the management and the appointed person with the date. If one of these components is missing, the document will be rejected in the audit. Substitution regulations are particularly often missing, which leads to ongoing compliance gaps in the event of vacancies and absences due to illness and are immediately noticeable in audits.

Stumbling blocks lie in vague task descriptions, a lack of connection to management, a lack of exemption from instructions on technical security issues and a lack of resources. An order deed that transfers the ISB function without a commitment to resources invites conflict because the ISB is made responsible for implementation without having the means to implement it. CIVAC provides a tested appointment certificate template in the workspace with all mandatory components, which is supplemented by guided questions during the creation process. The appointment certificate, signed, filed, verifiable. The template is updated centrally in the event of legal changes so that orders from previous years can be updated in a timely manner.

Reporting line to management: frequency, form and content

The information security officer's reporting line to management is just as important in the audit as the appointment certificate itself. It shows that the function actually works and does not get lost in a deadlock between IT and management. A robust reporting line requires three components. Firstly, the regular report at defined intervals, usually quarterly with an annual review. Secondly, the ad hoc report in the event of critical incidents, which is sent to management without delay. Thirdly, the documented acknowledgment by management, which closes the loop in the audit.

The quarterly report typically contains ten points. Firstly, the status of the risk situation. Secondly, open measures from the risk register. Third, the status of the ISO/IEC 27001:2022 controls. Fourth, the audit findings and their processing. Fifth, vulnerability and patch management. Sixth, incident management with the events of the period. Seventh, the status of awareness training. Eighth, supplier security with assessments of critical service providers. Ninth, the status of emergency planning with exercise results. Tenth, the outlook with topics for the following period. If NIS 2 is affected, the 24- and 72-hour reporting path is added as a separate reporting point.

CIVAC maintains the reporting line in the workspace as a structured template with automated data extraction from the ISMS. The report is not compiled manually, but rather aggregated from ongoing operations and only checked and commented on by the ISB. The auditor calls, the evidence is ready. The management is informed in the workspace with a time stamp and electronic confirmation. This creates a consistent reporting trail that provides proof of effectiveness in the audit according to ISO/IEC 27001:2022 Clause 9.3 without any additional effort. The personal liability of the management according to Section 130 OWiG and Section 38 NIS2UmsuCG is therefore supported by reliable evidence.

Personal requirements: qualifications, independence, further training

Personal requirements are placed on the information security officer, which are checked in the audit. ISO/IEC 27001:2022 requires in clause 7.2 demonstrable competence of the person responsible for the ISMS. This competence is usually proven by a relevant qualification, for example as an ISO/IEC 27001 Lead Implementer, as an ISO/IEC 27001 Lead Auditor, as a Certified Information Systems Security Professional (CISSP), as a Certified Information Security Manager (CISM) or as a BSI IT-Grundschutz practitioner. In addition, regular training is required because threats, standards and legal situations are constantly changing. Purchasing a certificate once does not meet the standard.

Personal independence is a second criterion. The ISB must not be bound by instructions on technical security issues, especially not to the IT management, because otherwise conflicts of interest arise between availability and security. A disciplinary connection to management or to the risk and compliance department is therefore the rule in regulated environments. A personal union with the data protection officer is possible, but this must be justified in the audit because the DPO and ISB have different protection goals and must take joint action in IT-related data breaches. The interface is clearly documented in the reporting line.

Continuing training requires at least 16 to 24 hours annually in relevant topics, depending on the industry and qualification path. Participation must be documented and recorded in the ISB training pass. CIVAC maps the requirements in the workspace. Proof of qualifications are stored with an expiry date, further training obligations are automatically monitored and the audit preparation maintains the ISB training biography as a separate data set. Others run compliance like a filing cabinet. We run it like software. Upon request, the auditor sees the qualification biography of the ISB person without prior notice, which shortens the duration of the audit and structurally ends discussions on the question of competence before they begin.

Costs, effort and realistic vacancy risks

The cost of the ISB function varies greatly depending on size, industry and level of maturity. In a medium-sized constellation with 250 to 1,000 employees and ISO/IEC 27001 certification target, the operational ISB function requires between 0.5 and 1.2 full-time positions. With internal personnel costs of 90,000 to 130,000 euros per full-time position including additional wage costs, there are annual direct costs of between 50,000 and 150,000 euros. In addition, there are licences for ISMS tools, external audits and further training with a further 15,000 to 40,000 euros annually depending on the level of maturity.

An external ISB as a service costs between 35,000 and 90,000 euros per year, depending on the hourly volume and industry. The range depends on the agreed number of hours, the industry and the level of specialization. Hybrid models, in which the formal role is external and the operational implementation is internal, are in the middle range and are the economic middle ground for many medium-sized companies. Vacancy risks are real. A sudden termination of the internal ISB person creates compliance gaps that are immediately noticeable in the cyber insurance policy and in supplier audits and can endanger certificates.

CIVAC structurally reduces vacancy risks. In the workspace, the task list with responsible persons, templates and deadlines is managed in such a way that replacements become productive in days instead of weeks. In the variant with external representatives, CIVAC takes over the ISB as a service with documented representation. Licence the workspace for your internal representatives or have our representatives order it. The CIVAC SLA of 2 business days replaces the classic response window of 2 to 6 weeks, closing the gap where unannounced audits, cyber incidents or supplier inquiries catch the organisation off guard. Turn reading into an assignment.

From the appointment certificate to a resilient security organisation

An appointment certificate alone does not provide protection. It is the entry point into a security organisation, which consists of a reporting line, risk register, control catalogue, training program, incident management and audit trail. Regulators, auditors and insurers are not checking the paper on the wall, but rather the maturity of that organisation. A platform alone, without an order, without task clarity and without a reporting line, creates just as little security as an ordered ISB without tools. It is precisely this combination that distinguishes a resilient security organisation from a formal fulfilment of duty that shows cracks in the first serious audit.

CIVAC is a compliance platform and officer-as-a-service with workspace, audit templates, appointment certificates, reporting lines and EU data residency. Licence the workspace for your internal representatives or have our representatives order it. The workspace manages the 93 controls of ISO/IEC 27001:2022 with measures, responsible persons and evidence, supplemented by the NIS 2-specific 24 and 72 hour reporting path. The auditor calls, the evidence is ready. The platform reminds you of substitution rules, audit dates and training obligations and closes the typical gaps before the audit instead of discovering them during the audit. Deadline expires as soon as we become aware of it.

If you want to appoint an information security officer for the first time, check an existing order for resilience or want to convert operational ISMS work to a platform solution, we will clarify this in a structured initial discussion. Turn reading into an assignment. Write to info@civac.de or use the contact form for an initial assessment of the current security organisation. You receive a concrete list of gaps with delivery dates so that the ISB function does not get lost in the conflict between IT and management, but is established as a resilient role with a clear reporting line and demonstrable effectiveness that contributes to audits and incidents.

FAQ

Is the appointment of an information security officer legally mandatory?

There is no express legal obligation for all sectors. In practice, the obligation arises from NIS-2 with Section 30 NIS2UmsuCG, from the KRITIS umbrella law, from DORA for financial service providers, from TISAX for the automotive industry and from ISO/IEC 27001:2022 clause 5.3. Additionally, many cyber insurance policies and customer audits require the appointment of a responsible person. This means that the function is actually mandatory in regulated and regulated companies.

How is the ISB different from the CISO?

The ISB is the operational role established in Germany for the ISMS with reference to ISO/IEC 27001:2022 and BSI-IT-Grundschutz. The CISO is the internationally common strategic role with a focus on cyber risk management, compliance and crisis management. In corporations the two are separated; in medium-sized businesses they are often combined in one person. The appointment certificate should clearly state the tasks performed so that auditors can understand the demarcation of roles.

Can the IT manager also be an ISB?

A personal union is possible, but must be justified regularly in audits. It creates a conflict of interest between availability and security because the same person orders security measures and is responsible for IT production and its operational goals. In regulated environments such as KRITIS, DORA and larger ISO 27001 mandates, the separation is expected. In medium-sized companies, personal union is possible if the management guarantees in writing the freedom to give technical instructions on security issues.

How long does it take to appoint an external information security officer?

Classic orders via consulting mandates take 2 to 6 weeks because getting to know each other, drawing up the contract and the handover phase are all strung together. With the CIVAC platform, productive orders can be placed in 2 working days because the appointment certificate, task catalogue and workspace configuration are standardised. The CIVAC SLA of 2 working days is particularly crucial in the case of unannounced audits or acute vacancies in which the ISB function must be filled without delay.

What qualifications should an ISB demonstrate?

ISO/IEC 27001 Lead Implementer, ISO/IEC 27001 Lead Auditor, CISSP, CISM and the BSI IT-Grundschutz practitioner are established. In addition, industry-specific qualifications are useful, such as TISAX in the automotive sector or DORA training in the financial sector. ISO/IEC 27001:2022 Clause 7.2 requires demonstrable competence documented through certificates, relevant professional experience and regular continuing education. The evidence must be included in the ISB training pass.

How does CIVAC specifically support an information security officer?

CIVAC provides a preconfigured ISB role in the workspace with an appointment certificate, 93 controls according to ISO/IEC 27001:2022, 37 audit templates, risk register, reporting line to management and the NIS 2-specific 24 and 72 hour reporting path. You licence the workspace for internal representatives or have our representatives appointed. The CIVAC SLA of 2 working days ensures the continuous availability of the function even in replacement and vacancy situations.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles