Back to playbooks
    Playbook

    The BISO operating model

    A method for designing the business information security officer role: mandate, decision rights, placement, operating rhythm, interfaces, measures and pitfalls.

    Governance5 Sept 202622 min read

    Directive (EU) 2022/2555ISO/IEC 27001:2022ISO/IEC 27002:2022NIST CSWP 29Regulation (EU) 2022/2554
    On this page

    Scope: one security role across the business units · Who: the officer who owns the mandate · Prerequisites: a named sponsor and a unit list · First result: one quarter

    1. Why this exists (the failure mode it prevents)

    Security fails quietly when it is only central. The function writes the policy, keeps the register and answers the auditor. The decisions that create the risk are taken elsewhere: in a product roadmap, a procurement negotiation, a hiring plan. Nothing looks broken until an assessment asks who decided.

    Three symptoms mark the failure. Controls are designed without the process owner, so they are documented and not operated. Risk decisions fall to whoever is available rather than to the role that carries the consequence. A business unit learns of a requirement at the audit, long after it could have been met cheaply.

    The management system shows the damage in three places. Clause 5.3, Organizational roles, responsibilities and authorities, cannot be shown below the top of the organisation 1. Management review at clause 9.3 receives a security report with no business input 2. And when an incident forces a business trade-off, no role has the standing to decide.

    Directive (EU) 2022/2555 has Member States ensure that the management body of an essential or important entity approves the cybersecurity risk-management measures taken to comply with Article 21. That body also oversees implementation, and can be held liable for infringements of that Article 3. Members of those bodies are required to follow training, so that they gain the knowledge to identify risks and assess risk-management practices 4.

    Article 21 then asks for appropriate and proportionate technical, operational and organisational measures for the risks to the systems the entity uses. Proportionality takes account of exposure to risk, size, and the likelihood and severity of incidents 5. Paragraph 2 requires an all-hazards approach 6. NIST CSF 2.0 places a parallel outcome on organisational leadership at GV.RR-01, where organisational leadership is responsible and accountable for cybersecurity risk 7.

    The business information security officer is one answer. It is a role, not a person and not a title grade. The mandate sits close enough to a business unit to see decisions early, and close enough to the security function to give the organisation's answer.

    2. Definitions (only the ones that cause disputes)

    Seven terms decide whether the role works. Requirement text is paraphrased; only titles are quoted.

    TermWorking definitionSource
    Business information security officerA role defined by its mandate rather than its title. It holds named security decision rights inside a business unit and reports on that unit's risk. None of the standards cited here names the role.Method, against clause 5.3 1
    The CISO functionThe central function that sets policy, owns the management system and its criteria, and reports to top management. It does not decide for the unit.Method, against clause 5.1 Leadership and commitment 8
    Business unitThe smallest grouping with its own profit or service accountability, change pipeline and suppliers. Where the three do not coincide, the change pipeline decides the boundary.Method, informed by clause 4.1 Understanding the organization and its context 9
    Risk owner and control ownerThe risk owner accepts residual risk; the control owner operates the mechanism. Control 5.2 asks the organisation to define responsibility for risk management activities, and in particular for accepting residual risks, giving risk owners as the example.Annex A / ISO/IEC 27002:2022 control 5.2 Information security roles and responsibilities 10
    Decision rightsThe written list of decisions the role may take alone, take jointly, recommend, or must escalate. Anything absent from the list is escalated by default.Method, against clause 5.3 as above
    The three linesRegulation (EU) 2022/2554 has financial entities other than microenterprises assign ICT risk management and oversight to a control function with an appropriate level of independence. It also segregates ICT risk management, control and internal audit functions, following either the three lines of defence model or an internal model for risk management and control.Regulation (EU) 2022/2554 Art. 6(4) 11
    Interested partiesThe parties whose requirements the unit must satisfy, each recorded with its own requirement. Clause 4.2 is Understanding the needs and expectations of interested parties.ISO/IEC 27001:2022 clause 4.2 12

    3. The method — numbered steps, each with input, activity, output and owner

    Nine steps. The first three settle whether the role exists and what it may decide. The next three give it a rhythm and its interfaces. The last three cover reporting, staffing and measures.

    3.1 Decide whether the role is needed

    The role is an expensive answer to a coordination problem. Where the security function already reaches every decision, it adds a hop and removes nothing. Four questions settle it, and three affirmative answers are usually enough.

    Size and distance: how many decisions with security consequences are taken each month outside the central function's sight. Regulatory reach: whether more than one instrument applies across different parts of the organisation. Unit count: how many groupings have their own change pipeline and supplier base. Decision latency: how long a unit waits for a security answer, from question to recorded decision.

    • Input: organisation chart; change and procurement volumes per unit; the instruments in scope; a sample of security questions with their response times.
    • Activity: score the units against the four questions; record current decision latency; decide, and write the reason down; where the answer is no, name the compensating mechanism.
    • Output: role decision record, one page, carrying the four measures and the decision.
    • Owner: the head of the security function proposes; top management decides.

    3.2 Write the mandate

    Control 5.2 of ISO/IEC 27002:2022 asks that information security roles and responsibilities are defined and allocated according to the organisation's needs. Each area of responsibility is defined, documented and communicated, and authorisation levels are documented 10.

    Write four things, and refuse to publish without them. Decision rights, as a table of decisions against four verbs: decides, decides jointly, recommends, escalates. The escalation path, naming the receiving role and the maximum time before an unanswered escalation moves up. Both reporting lines: the line that appraises the role, and the line that receives its risk reporting. And an explicit list of what the role does not own — usually policy authorship, control operation, and acceptance of risk belonging to a unit head.

    CSF 2.0 states the outcome at GV.RR-02, where roles, responsibilities and authorities for cybersecurity risk management are established, communicated, understood and enforced 13. Resourcing is a separate outcome at GV.RR-03 14.

    • Input: the role decision record; the unit list; the existing delegation of authority; the risk acceptance criteria in force.
    • Activity: draft the decision-rights table; agree the escalation path and its clock; fix both reporting lines; write the exclusions; obtain two signatures on one page.
    • Output: BISO charter carrying a decision-rights map, dated and signed by both parties.
    • Owner: the security function drafts; the unit head and top management approve.

    The role advises on treatment and does not accept residual risk for the unit. And it does not audit what it designed: control 5.3 lists designing, auditing and assuring information security controls among the activities that can require segregation 15.

    3.3 Choose a placement model, and state the trade-off

    Three placements recur. Each buys something and costs something, and the cost is structural rather than a matter of execution.

    ModelReporting lineWhat it buysWhat it costs
    EmbeddedAppraised by the unit; risk reporting to the security functionEarliest sight of decisions; credibility inside the unit; short decision latencyCapture: the role tends to adopt the unit's appetite and stop escalating
    MatrixedAppraised by the security function; assigned to the unitConsistent judgement across units; easier calibration of risk criteriaSlower answers; the role reads as an outsider and can get routed around
    HubA central pool serving units on rotation or on demandScales to many small units; resilient to departures; even coverageWeakest unit context; relationships tend to restart at each rotation
    Placement models and the trade-off each one makes

    State the choice and its cost in the charter. Where the sector prescribes a shape, the prescription wins. Regulation (EU) 2022/2554 has the management body set clear roles and responsibilities for all ICT-related functions, with governance arrangements for communication, cooperation and coordination 16. Read with Article 6(4), that limits how far an embedded role can also be the independent one.

    • Input: the charter draft; the unit list with headcount and change volume; the sector's requirements on independence.
    • Activity: select the model per unit rather than for the whole organisation; write down the trade-off accepted; record the compensating measure for it.
    • Output: placement record per unit, inside the charter.
    • Owner: the security function proposes; top management approves.

    3.4 Give the role an operating rhythm

    A mandate without a calendar becomes a mailbox. The rhythm is the set of points where the role is present by default, so its absence is what has to be explained.

    The first is business planning, where the unit's objectives are set and security objectives can be attached to them. Clause 6.2 is Information security objectives and planning to achieve them 17. Then change gates, where the security question is asked before design is fixed; risk reviews, where entries are re-scored and overdue treatment is challenged; and incidents and supplier events, where the role supplies business context.

    Control 5.8 of ISO/IEC 27002:2022 asks that information security is integrated into project management, with risks assessed and treated early and periodically through the life cycle 18. Responsibilities and authorities for project security are allocated to specified roles, with stage follow-up by a body such as the project steering committee.

    • Input: the unit's planning calendar; the change board schedule; the risk review cadence; the incident and supplier processes.
    • Activity: place the role on each calendar as a standing participant; define what it brings and takes away; agree the monthly measures; publish the calendar.
    • Output: operating calendar; unit measure set with definitions and reporting dates.
    • Owner: the role owns the calendar; the unit head owns attendance.

    Measurement makes the rhythm visible, and clause 9.1 is Monitoring, measurement, analysis and evaluation 19. Attendance holds because management makes it hold: control 5.4 has management require all personnel to apply information security in line with the policy and procedures 20.

    3.5 Wire the interfaces

    The role's value sits in four interfaces, each with a named counterpart and a named artefact.

    The risk register is the first. Unit entries are raised, owned and re-scored in the unit, and roll up unchanged into the organisation's register; the method is in Risk registers people actually trust. The role makes sure each entry has an owner who can accept it.

    Control owners are the second. The role knows which control operators sit inside the unit and which sit in a shared function. Where the operator is shared, the unit still carries the risk.

    The incident process is the third. Central response handles containment and recovery; the role supplies impact framing, customer and regulatory context, and the business decision when a trade-off is unavoidable.

    Supplier assurance is the fourth, and sector law is specific here. Regulation (EU) 2022/2554 has financial entities other than microenterprises establish a role to monitor arrangements concluded with ICT third-party service providers. The alternative is a designated member of senior management responsible for overseeing the related risk exposure and documentation 21. CSF 2.0 states the same at GV.SC-02, where supplier, customer and partner roles are established, communicated and coordinated 22. The lifecycle method is in The third-party risk lifecycle.

    • Input: the organisation's risk register; the control inventory with operators; the incident process; the supplier register.
    • Activity: name the counterpart for each interface; agree the artefact that crosses it and its cadence; record unit decisions in the register the central function reads.
    • Output: interface map, one page per interface, inside the charter.
    • Owner: the role maintains the map; each counterpart confirms their side.

    3.6 Report upward without translating twice

    Two audiences read the same underlying data. The unit head needs the exposure their own decisions created; top management needs the organisation's position, with the units that differ named.

    Clause 9.3 is management review, with 9.3.2 inputs and 9.3.3 results 2. Unit-level reporting fills the input pack with something other than the security function's own opinion. Results are decisions rather than observations 23. CSF 2.0 closes the loop at GV.OV-03, where risk management performance is evaluated and reviewed for adjustments needed 24.

    The board-facing view is in Board reporting for security. Where the unit view and the board view disagree, the disagreement is the finding.

    • Input: the unit measure set; register entries with owners; open exceptions and expiry dates; incident and supplier events in the period.
    • Activity: publish the unit pack on a fixed date; feed the same figures into the review input pack without re-cutting them; record decisions with owners and dates.
    • Output: unit risk report; management review input contribution; decisions in the review record.
    • Owner: the role produces the unit pack; the security function assembles the review input.

    3.7 Staff the role for competence, not for the certificate list

    Clause 7.2 is Competence and clause 7.3 is Awareness 25 26. Control 5.2 adds that a person taking a specific security role should be competent in the knowledge and skills that role requires 10.

    The skills mix is the requirement; a qualification evidences part of it and never the whole. Four capabilities carry the role.

    • Reading the unit's business model well enough to price a security trade-off in the unit's own terms.

    • Risk framing: turning a technical finding into a stated exposure with an owner and an acceptance decision.

    • Standards fluency across the instruments in the unit's scope, at clause level, without a specialist alongside.

    • Holding a position under commercial pressure, and knowing when to escalate rather than absorb.

    • Input: the charter; the unit's instrument list; the current skills inventory.

    • Activity: define the capability profile; assess against it; record gaps with development actions and dates; re-assess on a fixed cycle.

    • Output: capability profile; competence records per holder.

    • Owner: the security function owns the profile; the appraising line owns the records.

    3.8 Measure whether the function is working

    Three measures separate a working role from a title.

    Decision latency: elapsed time from a security question raised in the unit to a recorded decision, taken from the sample used in step 3.1. Risk-acceptance records: accepted risks carrying a named unit owner, a date and an expiry, as a proportion of accepted risk in the unit. Findings owned in the unit: the share of assessment findings whose remediation owner sits inside the unit. Where the escalation path is new, add a fourth: escalations raised, and of those, escalations answered within the charter's clock.

    CSF 2.0 places the surrounding expectations under Risk Management Strategy. GV.RM-02 has risk appetite and tolerance statements established, communicated and maintained; GV.RM-05 has lines of communication established for cybersecurity risks, including supplier risks 27.

    • Input: the decision log; the risk register; the finding register; the escalation log.
    • Activity: define each measure once, with its source record; report monthly; review the definitions annually and record any change.
    • Output: measure definitions; monthly measure results.
    • Owner: the role reports; the security function keeps the definitions stable across units.

    3.9 Watch for the three failure shapes

    Three shapes recur, each with an indicator that appears before the finding does.

    The shadow CISO. The role starts writing policy, running controls and answering the auditor for the unit, and the central function quietly stops covering that unit. The indicator is a policy document whose approver sits in one unit. The correction is the exclusion list in step 3.2, enforced.

    The compliance clerk. The role becomes a questionnaire pipeline: evidence requests in, spreadsheets out, no decision anywhere. The indicator is a decision log with no entries beside a rising evidence volume. The correction is to move the role onto the change gate, where decisions are still open.

    The escalation that never lands. The path exists on paper, escalations are raised, and nothing comes back. The indicator is the answered-within-clock measure. The correction is a named receiving role and a maximum time, both in the charter, both reported.

    Control 5.35 asks that the approach to managing information security and its implementation is reviewed independently, at planned intervals or when significant changes occur 28. Reviewers are independent of the area under review and outside its line of authority.

    • Input: the decision log; the escalation log; the policy register; the finding register.
    • Activity: test the three indicators each quarter; where one fires, name the correction and a date; include the role's own operation in the independent review programme.
    • Output: quarterly indicator check; independent review report covering the role.
    • Owner: the security function tests; an independent reviewer covers the role itself.

    4. Deliverables

    Seven artefacts, each produced by a step above and named as it will be named in the evidence set. Retention periods are organisational choices rather than requirements of any standard.

    DeliverableProduced byFormatRetention
    Role decision recordStep 3.1documentcurrent plus one cycle
    BISO charterStep 3.2document, dual signatureevery version, whole cycle
    Decision-rights mapStep 3.2table inside the charterevery version, whole cycle
    Placement record per unitStep 3.3table inside the chartercurrent plus one cycle
    Operating calendarStep 3.4calendar plus a one-page summarycurrent period
    Interface mapStep 3.5one page per interfacecurrent plus one cycle
    Unit risk profileSteps 3.4 and 3.6CSF Organizational Profileevery version, whole cycle

    The unit risk profile is the one artefact with a published shape. A CSF Organizational Profile describes an organisation's current or target cybersecurity posture in terms of the Core's outcomes 29. A Current Profile states the outcomes being achieved and to what extent; a Target Profile states the outcomes selected and prioritised; the gap becomes a prioritised action plan 29.

    The interactive companion to this method is the Lab's BISO Guide, running privately, which carries the charter, the register, the control library, assurance and incidents as working surfaces. Templates for the charter and the decision-rights map: template pending.

    5. What the auditor or authority will ask

    The phrasing follows how an assessor opens a line of enquiry: a request for a record, then a request for the decision behind it.

    An assessment that stays with the charter is going well. One that moves to the decision log, then to the unit head, is where a title without a mandate fails.

    6. Failure modes and how they surface as findings

    Four patterns account for most of the damage. Each is given as the pattern, the wording it produces in a report, and the smallest change that removes it.

    The root is the same in all four: authority described in prose instead of written as a list of decisions with owners.

    7. Mapping the operating model to the standards

    Clause numbers and titles come from the ISO/IEC 27001:2022 contents listing; control numbers and titles from ISO/IEC 27002:2022. Category identifiers come from the CSF 2.0 Core in Appendix A of NIST CSWP 29: GV.OC Organizational Context, GV.RM Risk Management Strategy, GV.RR Roles, Responsibilities, and Authorities, GV.OV Oversight. Requirement text is paraphrased.

    ElementClause or controlCSFEvidence sampledVerified
    Unit context4.1 Understanding the organization and its contextGV.OCContext record of the unit's issues9
    Interested parties4.2 Understanding the needs and expectations of interested partiesGV.OCRegister rows, each with a named requirement12
    Mandate and decision rights5.3 Organizational roles, responsibilities and authoritiesGV.RRCharter and decision-rights map, signed1
    Risk ownership6.1.2 Information security risk assessmentGV.RMRegister entries with named unit owners30
    Treatment6.1.3 Information security risk treatmentGV.RMTreatment plan traced to unit entries31
    Objectives per unit6.2 Information security objectives and planning to achieve themGV.RMMeasure, target and latest result17
    Competence7.2 CompetenceGV.RRCapability profile and per-holder records25
    Residual risk acceptance8.3 Information security risk treatmentGV.RMDated acceptance by the entitled owner32
    Unit measure set9.1 Monitoring, measurement, analysis and evaluationGV.OVConsecutive monthly results19
    Reporting upward9.3.3 Management review resultsGV.OVDecisions with owners and dates23
    Findings owned in the unit10.2 Nonconformity and corrective actionGV.OVFinding register with a unit owner33
    Segregation of assuranceAnnex A / ISO/IEC 27002:2022 control 5.3 Segregation of dutiesGV.RRReviewer independence per review15
    Independent reviewAnnex A / ISO/IEC 27002:2022 control 5.35 Independent review of information securityGV.OVReport on reviewer independence28
    Management body oversightInstrument requirementGV.RRApproval, oversight and training records3
    Control-function independenceInstrument requirementGV.RRSegregation of risk, control and audit11
    Operating-model element to clause, CSF Category and evidence

    8. Checklist

    Each item is observable. "Agreed" is not; a dated signature on a named page is.

    References

    Primary sources only. ISO/IEC 27001:2022 clause titles come from the publisher's own contents listing; ISO/IEC 27002:2022 control numbers and titles from a licensed copy, with requirement text paraphrased.

    1. ISO/IEC. Information security management systems — Requirements. ISO/IEC 27001:2022. Contents and clause titles read at https://www.iso.org/obp/ui/#iso:std:iso-iec:27001:ed-3:v1:en 34
    2. ISO/IEC. Information security controls. ISO/IEC 27002:2022. Controls 5.2, 5.3, 5.4, 5.8 and 5.35 read in a licensed copy; catalogue entry at https://www.iso.org/standard/75652.html 35
    3. National Institute of Standards and Technology. The NIST Cybersecurity Framework (CSF) 2.0. NIST CSWP 29, 26 February 2024. Section 3.1 and Appendix A read at https://doi.org/10.6028/NIST.CSWP.29 36
    4. European Parliament and Council. Directive (EU) 2022/2555 (NIS 2 Directive). OJ L 333, 27.12.2022, p. 80. Articles 20 and 21 read at https://publications.europa.eu/resource/celex/32022L2555 37
    5. European Parliament and Council. Regulation (EU) 2022/2554 on digital operational resilience for the financial sector. OJ L 333, 27.12.2022, p. 1. Articles 5 and 6 read at https://publications.europa.eu/resource/celex/32022R2554 38

    Cadences, retention periods and measure thresholds above are organisational choices rather than requirements of any standard or instrument named here.

    Sources

    1. 1ISO/IEC 27001:2022 clause 5.3, iso.org/obp · verified 2026-09-03
    2. 2ISO/IEC 27001:2022 clause 9.3, iso.org/obp · verified 2026-09-03
    3. 3EU Publications Office CELEX 32022L2555 Art. 20(1) · verified 2026-09-05
    4. 4EU Publications Office CELEX 32022L2555 Art. 20(2) · verified 2026-09-05
    5. 5EU Publications Office CELEX 32022L2555 Art. 21(1) · verified 2026-09-05
    6. 6EU Publications Office CELEX 32022L2555 Art. 21(2) · verified 2026-09-05
    7. 7NIST CSWP 29 Appendix A GV.RR-01, nvlpubs.nist.gov · verified 2026-09-05
    8. 8ISO/IEC 27001:2022 clause 5.1, iso.org/obp · verified 2026-09-03
    9. 9ISO/IEC 27001:2022 clause 4.1, iso.org/obp · verified 2026-09-03
    10. 10ISO/IEC 27002:2022 control 5.2, licensed copy · verified 2026-09-05
    11. 11EU Publications Office CELEX 32022R2554 Art. 6(4) · verified 2026-09-05
    12. 12ISO/IEC 27001:2022 clause 4.2, iso.org/obp · verified 2026-09-03
    13. 13NIST CSWP 29 Appendix A GV.RR-02, nvlpubs.nist.gov · verified 2026-09-05
    14. 14NIST CSWP 29 Appendix A GV.RR-03, nvlpubs.nist.gov · verified 2026-09-05
    15. 15ISO/IEC 27002:2022 control 5.3, licensed copy · verified 2026-09-05
    16. 16EU Publications Office CELEX 32022R2554 Art. 5(2), point (c) · verified 2026-09-05
    17. 17ISO/IEC 27001:2022 clause 6.2, iso.org/obp · verified 2026-09-03
    18. 18ISO/IEC 27002:2022 control 5.8, licensed copy · verified 2026-09-05
    19. 19ISO/IEC 27001:2022 clause 9.1, iso.org/obp · verified 2026-09-03
    20. 20ISO/IEC 27002:2022 control 5.4, licensed copy · verified 2026-09-05
    21. 21EU Publications Office CELEX 32022R2554 Art. 5(3) · verified 2026-09-05
    22. 22NIST CSWP 29 Appendix A GV.SC-02, nvlpubs.nist.gov · verified 2026-09-05
    23. 23ISO/IEC 27001:2022 clause 9.3.3, iso.org/obp · verified 2026-09-03
    24. 24NIST CSWP 29 Appendix A GV.OV-03, nvlpubs.nist.gov · verified 2026-09-05
    25. 25ISO/IEC 27001:2022 clause 7.2, iso.org/obp · verified 2026-09-03
    26. 26ISO/IEC 27001:2022 clause 7.3, iso.org/obp · verified 2026-09-03
    27. 27NIST CSWP 29 Appendix A GV.RM, nvlpubs.nist.gov · verified 2026-09-05
    28. 28ISO/IEC 27002:2022 control 5.35, licensed copy · verified 2026-09-05
    29. 29NIST CSWP 29 §3.1, nvlpubs.nist.gov · verified 2026-09-05
    30. 30ISO/IEC 27001:2022 clause 6.1.2, iso.org/obp · verified 2026-09-03
    31. 31ISO/IEC 27001:2022 clause 6.1.3, iso.org/obp · verified 2026-09-03
    32. 32ISO/IEC 27001:2022 clause 8.3, iso.org/obp · verified 2026-09-03
    33. 33ISO/IEC 27001:2022 clause 10.2, iso.org/obp · verified 2026-09-03
    34. 34ISO/IEC 27001:2022 contents, iso.org/obp · verified 2026-09-03
    35. 35ISO/IEC 27002:2022 controls 5.2, 5.3, 5.4, 5.8 and 5.35, licensed copy · verified 2026-09-05
    36. 36NIST CSWP 29 §3.1 and Appendix A, nvlpubs.nist.gov · verified 2026-09-05
    37. 37EU Publications Office CELEX 32022L2555 Art. 20 and Art. 21 · verified 2026-09-05
    38. 38EU Publications Office CELEX 32022R2554 Art. 5 and Art. 6 · verified 2026-09-05