Skip to content

ISMS

ISMS without a security team: roles, effort, tools

BSI IT-Grundschutz requires at least one appointed person, not a team. This guide pulls the roles, duties and sources from ISO 27001, the BSI-Standards and the BSIG together into one matrix.

By · Published 18 September 2026 · 18 min read

An ISMS requires at least one appointed person, not a security team: that is what BSI IT-Grundschutz says, and ISO/IEC 27001 asks for assigned responsibilities rather than a job position. What one person may not hold is the review of their own work. This guide from KaitoSec sorts roles, effort and tooling along that line. If you are still at the whether-or-not stage, start at ISMS in mid-sized companies.

Which roles does an ISMS have to fill at a minimum?

BSI-Standard 200-1 sets exactly three personnel requirements in Chapter 7.2: top management keeps overall responsibility, at least one person is appointed to promote and coordinate the information security process, and every employee stays co-responsible for their own workplace. No security team appears in the three basic rules, and ISO/IEC 27001 names no job title.

In KaitoSec’s conversations with mid-sized companies and public bodies, the role question almost always starts with a job advert. BSI-Standard 200-1 starts with three basic rules (translated from the German):

“1. Overall responsibility for information security remains with top management. 2. At least one person must be appointed who promotes and coordinates the information security process, typically as the information security officer (ISB). 3. Every employee is equally responsible for their original task and for maintaining information security at their workplace and in their environment.”

In practice, the second basic rule often turns into a CISO position. BSI-Standard 200-2 clears that up itself in Chapter 4.4 (translated from the German):

“The role of the person responsible for information security is named differently depending on the type and orientation of the institution. Besides the information security officer, common titles are Chief Information Security Officer (CISO) or information security manager (ISM).”

ISO/IEC 27001:2022 mentions neither a CISO nor an information security officer. Clause 5.3, “Organizational roles, responsibilities and authorities”, requires top management to assign and communicate responsibilities and authorities for roles, and hands out two concrete ones: ensuring the conformity of the ISMS and reporting to top management.

No control in Annex A names a job title either. A.5.2 speaks of roles and responsibilities, not positions. Where an obligation to appoint an information security officer exists, it comes from BSI IT-Grundschutz, sector-specific rules or contractual requirements, not from ISO/IEC 27001.

The task can be delegated, the responsibility cannot: under BSI-Standard 200-2, Chapter 2.3 it stays with top management, while the task moves to an appointed officer. KaitoSec maps this role day to day in the role view for ISB and CISO.

Which roles do ISO 27001, BSI IT-Grundschutz and Section 38 BSIG require in detail?

The role requirements sit in four documents, none of which demands a budgeted position. BSI-Standard 200-1 asks for at least one appointed person, ISO/IEC 27001 for assigned and communicated responsibilities, and Section 38 of the German BSI Act (BSIG) addresses the management body alone. The binding force is graded, from law to method.

The four documents are the BSI-Standards 200-1 and 200-2 of IT-Grundschutz, ISO/IEC 27001 and Section 38 BSIG. In the BSI-Standards, “must” means a requirement and “should” a recommendation you may depart from with justification; the matrix keeps that gradation wherever the source makes it explicitly. The 26 points are sorted into seven blocks: management and liability, the appointed role, all employees, independence of the review, combined roles, external appointment, and ISO clauses and controls.

  1. Top management carries overall responsibility for information security and cannot delegate it (BSI-Standard 200-2, Chapter 2.3).
  2. Top management initiates, steers and monitors the security process itself (BSI-Standard 200-2, Chapter 2.2).
  3. Management bodies must implement and monitor the Section 30 risk management measures (Section 38(1) BSIG).
  4. Management bodies breaching duties are liable to their entity for culpably caused damage (Section 38(2) BSIG).
  5. Management bodies must regularly attend training on risk identification and management practices (Section 38(3) BSIG).
  6. Top management must provide sufficient resources in staff, time and funding (BSI-Standard 200-2, Chapter 3.1).
  7. At least one person must be appointed to promote and coordinate security (BSI-Standard 200-1, Chapter 7.2).
  8. ISB, CISO and information security manager name the same role (BSI-Standard 200-2, Chapter 4.4).
  9. The ISB, too, needs a qualified deputy of their own (BSI-Standard 200-2, Chapter 4.4).
  10. The ISB must have direct access to management at any time (BSI-Standard 200-2, Chapter 4.4).
  11. The ISB should sit as a staff function, not in IT (BSI-Standard 200-2, Chapter 4.4).
  12. The smallest IS management team is the ISB plus their deputy (BSI-Standard 200-2, Chapter 4.5).
  13. All employees share responsibility for information security at their own workplace (BSI-Standard 200-1, Chapter 7.2).
  14. Reviewers should not check anything they designed themselves (BSI-Standard 200-2, Chapters 4.10 and 10.3).
  15. Where internal review resources are missing, external experts should be commissioned instead (BSI-Standard 200-1, Chapter 8.3).
  16. Small institutions have lower review requirements than large ones and can comply (BSI-Standard 200-1, Chapter 8.3).
  17. The ISB may also take on the business continuity officer role (BSI-Standard 200-2, Chapter 4.10).
  18. ISB and data protection officer are not fundamentally incompatible roles (BSI-Standard 200-2, Chapter 4.4).
  19. Active administrators should not also hold the ISB role, given likely conflicts (BSI-Standard 200-2, Chapter 4.4).
  20. Internal audit and audit roles do not combine easily with security management (BSI-Standard 200-2, Chapter 4.10).
  21. The ISB role must go to qualified externals if internal staffing fails (BSI-Standard 200-2, Chapter 4.11).
  22. ISO/IEC 27001 Clause 5.3 requires assigned and communicated responsibilities, not a named position.
  23. Top management assigns two responsibilities: ISMS conformity and reporting back to it (ISO/IEC 27001, Clause 5.3).
  24. ISO/IEC 27001 Clause 7.1 requires the organization to determine and provide the necessary resources.
  25. Control A.5.2 covers information security roles and responsibilities (ISO/IEC 27001, Annex A).
  26. Control A.5.3 covers segregation of conflicting duties and areas of responsibility (ISO/IEC 27001, Annex A).

The matrix answers the role question, not the questions before it. Whether Section 38 BSIG covers an entity at all is decided by size and sector. How many of these duties arise depends on which areas, sites and processes the ISMS covers; how to draw the scope is set out in defining the ISMS scope correctly. KaitoSec keeps this role and responsibility assignment as a data set, so it holds up in an audit.

Can the head of IT also serve as information security officer?

Yes, but not if they administer systems themselves. BSI-Standard 200-2 explicitly allows combined roles in Chapter 4.10 and names three points to settle first: defined interfaces, a named body for conflicts, and enough resources for every role. Chapter 4.4 calls active administration plus the ISB role problematic, because conflicts of interest are foreseeable.

Spelled out, these are:

  1. Interfaces between the ISB role and the second role should be defined and documented.
  2. For conflict-prone topics a clarifying body should be named, for example internal audit.
  3. People holding several roles must be sufficiently qualified and have enough free resources.

The ISB role is not fundamentally incompatible with the business continuity officer under Chapter 4.10, nor with the data protection officer under Chapter 4.4. Whether the combination holds depends on the institution’s size and orientation, how deeply IT permeates its processes, and how developed its security management is.

The most common proposal in mid-sized companies is also the hardest: the head of IT administers systems and is meant to pick up the ISB role too. BSI-Standard 200-2 says this (translated from the German):

“It is problematic, for example, if an ‘active’ administrator takes on the role of the information security officer in addition to their normal duties, as conflicts of interest are highly likely to arise.”

The conflict is an everyday one: whoever owns patch levels, permissions and firewall rules assesses their own work as information security officer and reports their own omissions upward. The same person then decides whether operations keep running or the security finding wins. Hence Chapter 4.4 also states (translated from the German):

“The information security officer should not be organizationally assigned to the IT department.”

“Problematic” and “should not” are not prohibitions. BSI-Standard 200-2 allows a deviation, but requires it to be carefully weighed and soundly justified.

Before any combined role there is another duty anyway: under Chapter 4.4 the ISB too needs a qualified deputy. In a one-person setup that is the first real bottleneck, not the ISB role.

Who may run the internal audit when only one person looks after the ISMS?

Anyone who did not write the concepts under review may audit them. BSI-Standard 200-2 requires competence and independence of the reviewing people in Chapter 10.3, and recommends that reviewers do not check what they designed themselves. In a one-person ISMS that leaves three routes: the qualified deputy, another internal person, or an external review.

BSI-Standard 200-2 puts it like this in Chapter 10.3 (translated from the German):

“The reviews of the individual topics must be carried out by suitable persons who can guarantee the necessary competence and independence. Completeness and plausibility checks should not be performed by the authors of the concepts.”

“Should not” is a recommendation and allows a justified deviation. Three routes work:

  1. The ISB’s qualified deputy reviews the concepts they did not help write.
  2. Another internal person who did not author the concepts runs the completeness and plausibility checks.
  3. For areas one person designed alone, an external review takes over the checking.

ISO/IEC 27001:2022 governs the internal audit in Clause 9.2 and requires an audit program that ensures objectivity and impartiality. It names no fixed interval, only planned intervals.

The review effort scales with the size of the information domain. BSI-Standard 200-1 names a minimum package in Chapter 8.3 that can be enough in small institutions (translated from the German):

“An annual technical check of IT systems, a review of the existing documentation to check that it is up to date, and a workshop in which problems and experiences with the security concept are discussed may, under certain circumstances, already be sufficient in small institutions.”

“Annual” applies to the technical check, not the whole internal audit. KaitoSec offers the internal audit as a consulting service; the detail is in the internal audit under ISO 27001.

Which duties of the management body cannot be delegated?

Section 38 BSIG binds management bodies personally to three things: implementing the risk management measures under Section 30, monitoring implementation, and attending training regularly. Breach those duties and they are liable to their own entity under applicable company law. The duty covers only particularly important and important entities, not every mid-sized company.

The provision is officially headed “Implementation, monitoring and training obligation for management bodies of particularly important entities and important entities”. The wording (translated from the German):

“(1) Management bodies of particularly important entities and important entities are obliged to implement the risk management measures to be taken by these entities under Section 30 and to monitor their implementation. (2) Management bodies that breach their obligations under paragraph 1 are liable to their entity for culpably caused damage in accordance with the rules of company law applicable to the entity’s legal form. […] (3) The management bodies of particularly important entities and important entities must regularly attend training in order to acquire sufficient knowledge and skills to identify and assess risks and risk management practices in the field of information technology security […]”

Neither the training attendance under paragraph 3 nor the monitoring duty under paragraph 1 can be passed to the appointed role. Law and BSI-Standards arrive at the same point: the operational task moves to the appointed role, the responsibility stays at the top.

Section 38(1) BSIG refers to Section 30(2) BSIG, which lists ten categories of measures, among them handling security incidents and supply chain security. According to the German government’s draft bill, roughly 8,250 particularly important and 21,600 important entities from the private sector are affected (BT-Drucksache 21/1501, p. 109 ff.). Whether an individual entity is among them is clarified by the NIS2 checker and Do I need an ISMS for NIS2?.

How much working time does an ISMS require per year?

The German government’s draft bill estimates the annual compliance cost of an important entity at roughly 1,100 working hours plus 24,300 euros in material costs. That is an estimate for all risk management measures under Section 30 BSIG, not for ISMS operation alone, and it is the only official order of magnitude available.

BT-Drucksache 21/1501 also reckons with 2,752 working hours a year per particularly important entity, an average wage rate of 56.08 euros per hour and material costs of 60,700 and 24,300 euros per case. The figure applies to entities in scope of NIS2, whether or not a security team works there. The document does not support a conversion into staff shares.

What recurs is an annual cycle no tool abolishes:

  1. The internal audit checks at planned intervals whether the defined measures are effective.
  2. The management review puts results, deviations and open decisions to top management for approval.
  3. The risk assessment is updated as soon as processes, systems or threats change.
  4. Training and awareness reach all employees and are documented in a verifiable way.

Separate from that is the one-off build, a sequence in which every step builds on the previous result:

  1. The stocktake compares the current state against the requirements of the target standard.
  2. The scope definition determines which areas, sites and systems the ISMS covers.
  3. The risk assessment records the risks inside that scope and prioritizes what needs doing.
  4. Measures and evidence are implemented, documented and mapped to the requirements they satisfy.
  5. Internal audit and management review then move the build into the annual cycle.

BSI-Standard 200-2 names the biggest lever itself: Basis-Absicherung, the basic protection route for institutions still at the beginning of their security process. Chapter 3.3.5 weighs the advantages against the disadvantages (translated from the German):

“The effort is comparatively low. This makes a fast entry into information security possible. […] Certification against ISO 27001 is not possible on this basis.”

Anyone who needs a certificate must aim higher from the start. For everyone else, Basis-Absicherung is an entry route the standard expressly provides for.

Software costs fit in alongside: on its pricing page KaitoSec lists, with annual billing, from 240 euros a month for Standard, from 575 euros for Professional and 29 euros per additional user per month; what ISMS software costs puts these figures in context.

What does an ISMS tool take over, and what necessarily stays a human task?

An ISMS tool takes over register upkeep, deadlines, evidence linking and reports. It takes over none of the five duties the standards tie to a person: appointment, access to management, the risk decision, independent review, and the training attendance of the management body under Section 38(3) BSIG. None of them can be handed to software.

In detail:

  1. Appointing the responsible person is top management’s own job (BSI-Standard 200-2, Chapter 3.1).
  2. No tool has direct access to management; the ISB needs exactly that (BSI-Standard 200-2, Chapter 4.4).
  3. The management body takes the risk decision and must monitor its implementation (Section 38(1) BSIG).
  4. A tool does not review itself; review needs competent, independent people (BSI-Standard 200-2, Chapter 10.3).
  5. Management bodies must attend the training personally, not their software (Section 38(3) BSIG).

What remains is repetitive work, and that is where a tool pays off. A measure is maintained once and linked as evidence for several frameworks instead of being gathered again for every review (compliance mapping). Policies run with a scope, an approval and a review date instead of a file list on a shared drive (policy management). Resubmission dates and owners hang on the measure itself.

The fewer people carry an ISMS, the more hangs on traceability. Anyone who is information security officer, data protection officer and business continuity officer at once must evidence the interfaces between those roles, with date and approval. KaitoSec therefore links the role assignment to the measures, so it stays visible in an audit who decided what.

A tool shifts where the ISMS time goes. BSI-Standard 200-2 requires top management to provide sufficient resources in staff, time and funding, and ISO/IEC 27001 puts the same duty in Clause 7.1:

“The organization shall determine and provide the resources needed for the establishment, implementation, maintenance and continual improvement of the information security management system.”

Neither source names staff shares, a budget figure or a security department. Both require that the appointed person really has time.

What do you do when the ISB role cannot be filled internally?

BSI-Standard 200-2 explicitly provides for external appointment: where key roles such as the ISB cannot be covered by internal staff, qualified externals must be commissioned. For small companies and public authorities the standard names the external ISB as a sensible solution. KaitoSec offers this role as a vCISO retainer from 576 euros a month.

“If key roles such as the ISB cannot be performed by internal staff, qualified externals must be commissioned for this. […] Particularly in small companies or public authorities it may under certain circumstances be sensible not to fill the role of the information security officer with an employee of one’s own, but to draw on the service of an external ISB for this.”

(translated from the German)

External appointment is not a stopgap but the route the standard provides for. The reason given: internal security experts often lack the time to analyse all security-relevant factors. Bringing in externals is to be documented, so top management provides the necessary resources.

The line runs at responsibility. An external information security officer takes on the operational work, not the management body’s duties under Section 38 BSIG. Those duties stay personal, whoever fills the role.

An appointed internal contact is still needed, because an external information security officer also needs a qualified deputy. For one-off work instead of an ongoing role, a remote consulting day starts from 1,150 euros.

On its own pricing page KaitoSec states that the platform can be run without consulting. The external role is an option, not a condition. Anyone who wants to hold their own role split against this matrix can walk through it in a demo call.

Frequently asked questions about ISMS roles without a security team of your own

Does a company without a security team need a CISO?

No. BSI-Standard 200-1 requires at least one appointed person in Chapter 7.2 to promote and coordinate the information security process. CISO, information security officer and information security manager are, per BSI-Standard 200-2, names for one role, not three positions. An obligation to appoint a named officer arises from BSI IT-Grundschutz or from contractual and tender requirements, not from ISO/IEC 27001.

At what size is one person no longer enough for the ISMS?

The BSI-Standards name no headcount as a threshold. Under BSI-Standard 200-2, Chapter 4.5, the shape of the IS management team depends on size, the security level aimed for and the resources available; in the extreme case it is two people, the information security officer and their deputy. The practical bottleneck is therefore rarely the ISB role, but the deputy and the review.

Can the data protection officer take on the ISB role as well?

Yes. BSI-Standard 200-2 records in Chapter 4.4 that the two roles are not fundamentally incompatible. Clearly defined interfaces and direct reporting lines to top management on both sides should exist; what must be ensured is enough free resource for both tasks. For conflict-prone topics, BSI-Standard 200-2 also suggests checking whether they should go to internal audit for information.

Does the internal audit have to be carried out by an external person?

Not necessarily external, but independent of the work under review. BSI-Standard 200-2 records in Chapter 10.3 that completeness and plausibility checks should not be performed by the authors of the concepts. Where one person built the ISMS alone, three routes remain: the qualified deputy, another internal person who did not author the concepts, or an external review.

Which duties can management hand to an external ISB?

The operational work, not the responsibility. Section 38 BSIG obliges the management bodies of particularly important and important entities personally to implement the risk management measures under Section 30, to monitor implementation and to attend training regularly. If they breach those duties, they are liable to their entity under applicable company law. An external ISB changes nothing about that personal duty.

How much working time does running an ISMS cost per year?

The only official order of magnitude comes from the draft bill implementing NIS2: roughly 1,100 working hours a year for an important entity and 2,752 for a particularly important one. The figure is an estimate from the legislative process, not a measurement, covers all ten categories of measures under Section 30(2) BSIG and applies to entities in scope of NIS2.

  • ISMS
  • ISO 27001
  • BSI IT-Grundschutz
  • NIS2
  • Mittelstand

Back to the blog