Skip to main content
Category: Governance and Roles

Information Security Manager

Also known as: ISM, Information Systems Security Manager, ISSM, Cybersecurity Manager, Certified Information Security Manager (CISM)
Simply put

An Information Security Manager is the person responsible for overseeing the cybersecurity of a program, organization, system, or defined area within a company. This individual typically leads a team and works to ensure their area is protected, often by assessing risks, establishing governance, and responding to security incidents.

Formal definition

The Information Security Manager (also referenced in some frameworks as the Information Systems Security Manager, or ISSM) is the individual accountable for the cybersecurity of a program, organization, system, or enclave. In practice, the role typically oversees a specific security domain, manages security staff, and is responsible for functions such as risk assessment, implementation of effective governance, and proactive incident response. The exact scope, reporting lines, and authority of the role vary by organization and are not fixed by any single standard; related professional credentialing (for example, ISACA's Certified Information Security Manager, or CISM) frames the role around risk assessment, governance, and incident response competencies.

Why it matters

The Information Security Manager sits at the center of how an organization translates security policy into day-to-day practice. Because both SOC 2 examinations and ISO/IEC 27001 certifications depend on demonstrable governance, risk assessment, and incident response, the presence of a clearly accountable individual overseeing these functions often shapes whether an assessor or certification body finds that controls are not only designed but actually owned and operating. In most engagements, auditors look for a defined role with the authority to make and enforce security decisions rather than a diffuse set of responsibilities spread across a team.

The role matters because scope, reporting lines, and authority are not fixed by any single standard, and gaps in accountability tend to surface as weaknesses during an assessment. Under ISO 27001, for example, the ISMS requirements in clauses 4 through 10 emphasize leadership, defined roles, and risk-based decision-making; a manager responsible for assessing risks and implementing governance is typically the person who operationalizes those requirements. Under SOC 2, the Security category (the Common Criteria) similarly depends on someone accountable for the controls that are attested over the review period.

It is worth noting that having an Information Security Manager in place does not by itself guarantee a favorable outcome or freedom from breaches. A SOC 2 report attests only to the controls and period covered, and an ISO 27001 certificate covers only the defined scope of the ISMS; the manager's effectiveness is judged against those boundaries, not as an absolute assurance of security.

Who it's relevant to

Compliance and GRC Managers
Compliance and GRC professionals rely on a clearly designated Information Security Manager to own risk assessment, governance, and incident response activities that both SOC 2 examinations and ISO 27001 certifications examine. A defined, accountable role helps demonstrate that controls are not only designed but actively managed within the assessed scope.
Auditors and Assessors
CPA firms performing SOC 2 attestations and certification bodies assessing ISO 27001 typically look for a person accountable for security governance and incident response. Because reporting lines and authority vary by organization, assessors evaluate how the role is actually scoped rather than assuming a standard definition.
Security Engineers and Staff
Security team members and augmented staff often report to or coordinate with the Information Security Manager, who oversees their area and directs risk-based decisions. Understanding this reporting relationship clarifies how technical work connects to broader governance and incident response obligations.
Executive Leadership
Leadership benefits from understanding that the Information Security Manager's authority and scope are set by the organization, not by any single standard. Clear positioning of the role supports the leadership and defined-responsibility expectations found in ISO 27001's ISMS requirements and the governance-related Common Criteria under SOC 2.

Inside ISM

ISMS Ownership and Governance
The Information Security Manager typically holds day-to-day responsibility for the Information Security Management System (ISMS) defined under ISO/IEC 27001 clauses 4 through 10, coordinating its establishment, operation, monitoring, and continual improvement. In most organizations this role operates under the authority of top management, which retains ultimate accountability.
Risk Assessment and Treatment Coordination
The role commonly facilitates the information security risk assessment and risk treatment process that informs which Annex A reference controls are selected. The selected and excluded controls are documented in the Statement of Applicability, with justification for inclusion or exclusion.
Statement of Applicability Maintenance
The Information Security Manager typically maintains the Statement of Applicability, which records the reference controls chosen from Annex A. Note that Annex A was restructured in the 2022 revision of ISO/IEC 27001 (from 114 controls in the 2013 version to 93 controls organized into four themes), so control references depend on the edition in use.
Control Operation and Evidence Management
The role often oversees the operation of security controls and the collection of evidence demonstrating their design and effectiveness. This evidence supports both ISO 27001 certification activities and, where applicable, a SOC 2 examination against the Trust Services Criteria, where Security (the Common Criteria) is required and Availability, Processing Integrity, Confidentiality, and Privacy are optional depending on scope.
Audit and Assessment Liaison
The Information Security Manager frequently serves as the primary point of contact for internal audits, ISO 27001 certification body assessments, and SOC 2 examinations performed by a licensed CPA firm under the AICPA SSAE 18 standard. These are distinct exercises: ISO 27001 results in a certification, while SOC 2 results in an attestation report.

Common questions

Answers to the questions practitioners most commonly ask about ISM.

Does the Information Security Manager personally issue the SOC 2 report or the ISO 27001 certificate?
No. A SOC 2 report is produced by a licensed CPA firm performing an attestation examination under the AICPA SSAE 18 standard, and an ISO/IEC 27001 certificate is issued by an accredited certification body. The Information Security Manager typically prepares the organization for these engagements, coordinates evidence, and interfaces with the assessor, but does not produce the report or grant the certification themselves.
Is the Information Security Manager role identical across SOC 2 and ISO 27001?
Not exactly. The responsibilities overlap but the frameworks differ. Under ISO 27001, the role often centers on operating and maintaining the ISMS as defined in clauses 4 through 10 and managing Annex A control selection via the Statement of Applicability. Under SOC 2, the emphasis is typically on demonstrating that controls mapped to the Trust Services Criteria are suitably designed and, for a Type II, operating effectively over the review period. Satisfying one framework does not automatically satisfy the other, so the manager's work under each is related but not interchangeable.
How does an Information Security Manager typically support the difference between a SOC 2 Type I and Type II examination?
For a Type I, which assesses the suitability of design of controls at a point in time, the manager generally focuses on ensuring controls are documented and in place as of the specified date. For a Type II, which assesses design and operating effectiveness over a defined review period whose length is set by scoping decisions, the manager typically maintains ongoing evidence of control operation throughout that period so the CPA firm can test effectiveness.
What role does the Information Security Manager play in scoping the Trust Services Criteria?
The manager commonly participates in scoping decisions that determine which Trust Services Criteria categories apply. Security, the Common Criteria, is the only required category; Availability, Processing Integrity, Confidentiality, and Privacy are optional and selected based on scope. The manager typically helps assess which categories are relevant to the services and commitments in question rather than assuming all are included.
How does an Information Security Manager typically handle Annex A control selection under ISO 27001?
In most engagements, the manager drives a risk assessment and uses its results to select applicable Annex A reference controls, documenting inclusions and exclusions in the Statement of Applicability. Because Annex A was restructured in the 2022 revision, the manager should confirm which edition of the standard is being certified against, since the control organization and counts differ between the 2013 and 2022 versions.
What limitations should an Information Security Manager communicate about a completed SOC 2 report or ISO 27001 certificate?
The manager should clarify boundaries to stakeholders. A SOC 2 report attests only to the controls and period covered and does not guarantee freedom from breaches. An ISO 27001 certificate covers only the defined scope of the ISMS. Depending on scope, other standards such as SOC 1, SOC 3, ISO 27002, ISO 27017, or ISO 27018 may address needs that these outcomes do not, and the manager typically communicates these boundaries so results are not overstated.

Common misconceptions

The Information Security Manager is personally accountable for the organization's information security compliance.
Under ISO/IEC 27001, top management retains ultimate accountability for the ISMS. The Information Security Manager typically holds operational responsibility and coordinates activities, but the standard places leadership and accountability obligations on top management rather than on a single manager.
An Information Security Manager who prepares the organization for ISO 27001 certification has thereby also prepared it for a SOC 2 report.
The two frameworks are distinct and mapping between them is only partial. ISO 27001 is a certification against a management system standard, while SOC 2 is an attestation examination against the Trust Services Criteria. Satisfying one does not automatically satisfy the other, and the Trust Services Criteria are not the same as ISO 27001 Annex A controls.
The Information Security Manager can guarantee that certified or attested controls prevent security breaches.
A SOC 2 report attests only to the controls and the period covered, and an ISO 27001 certificate covers only the defined scope of the ISMS. Neither outcome guarantees freedom from breaches, and no role can provide such assurance beyond the scope and period assessed.

Best practices

Clearly document the scope of the ISMS and, where a SOC 2 examination applies, the scoping decisions that determine the review period and any optional Trust Services Criteria categories selected beyond the required Security category.
Maintain the Statement of Applicability with explicit justification for each included or excluded Annex A control, and specify which edition of ISO/IEC 27001 the control references correspond to, since the 2013 and 2022 versions differ.
Keep the ISMS clause 4 through 10 requirements and the SOC 2 evidence base separate but cross-referenced, recognizing that mapping between the frameworks is partial and one certification or report does not substitute for the other.
Ensure top management remains engaged and formally accountable for the ISMS, rather than treating the Information Security Manager as the sole owner of compliance outcomes.
Coordinate risk assessment and treatment on a recurring basis so that control selection stays informed by current risk, and align evidence collection to support both certification body assessments and any CPA-led SOC 2 examination.
Communicate the limitations of each outcome to stakeholders, noting that a SOC 2 report covers only the controls and period examined and an ISO 27001 certificate covers only the defined ISMS scope.