The BISO operating model
A method for designing the business information security officer role: mandate, decision rights, placement, operating rhythm, interfaces, measures and pitfalls.
Governance5 Sept 202622 min read
On this page
Scope: one security role across the business units · Who: the officer who owns the mandate · Prerequisites: a named sponsor and a unit list · First result: one quarter
1. Why this exists (the failure mode it prevents)
Security fails quietly when it is only central. The function writes the policy, keeps the register and answers the auditor. The decisions that create the risk are taken elsewhere: in a product roadmap, a procurement negotiation, a hiring plan. Nothing looks broken until an assessment asks who decided.
Three symptoms mark the failure. Controls are designed without the process owner, so they are documented and not operated. Risk decisions fall to whoever is available rather than to the role that carries the consequence. A business unit learns of a requirement at the audit, long after it could have been met cheaply.
The management system shows the damage in three places. Clause 5.3, Organizational roles, responsibilities and authorities, cannot be shown below the top of the organisation 1. Management review at clause 9.3 receives a security report with no business input 2. And when an incident forces a business trade-off, no role has the standing to decide.
Directive (EU) 2022/2555 has Member States ensure that the management body of an essential or important entity approves the cybersecurity risk-management measures taken to comply with Article 21. That body also oversees implementation, and can be held liable for infringements of that Article 3. Members of those bodies are required to follow training, so that they gain the knowledge to identify risks and assess risk-management practices 4.
Article 21 then asks for appropriate and proportionate technical, operational and organisational measures for the risks to the systems the entity uses. Proportionality takes account of exposure to risk, size, and the likelihood and severity of incidents 5. Paragraph 2 requires an all-hazards approach 6. NIST CSF 2.0 places a parallel outcome on organisational leadership at GV.RR-01, where organisational leadership is responsible and accountable for cybersecurity risk 7.
The business information security officer is one answer. It is a role, not a person and not a title grade. The mandate sits close enough to a business unit to see decisions early, and close enough to the security function to give the organisation's answer.
2. Definitions (only the ones that cause disputes)
Seven terms decide whether the role works. Requirement text is paraphrased; only titles are quoted.
| Term | Working definition | Source |
|---|---|---|
| Business information security officer | A role defined by its mandate rather than its title. It holds named security decision rights inside a business unit and reports on that unit's risk. None of the standards cited here names the role. | Method, against clause 5.3 1 |
| The CISO function | The central function that sets policy, owns the management system and its criteria, and reports to top management. It does not decide for the unit. | Method, against clause 5.1 Leadership and commitment 8 |
| Business unit | The smallest grouping with its own profit or service accountability, change pipeline and suppliers. Where the three do not coincide, the change pipeline decides the boundary. | Method, informed by clause 4.1 Understanding the organization and its context 9 |
| Risk owner and control owner | The risk owner accepts residual risk; the control owner operates the mechanism. Control 5.2 asks the organisation to define responsibility for risk management activities, and in particular for accepting residual risks, giving risk owners as the example. | Annex A / ISO/IEC 27002:2022 control 5.2 Information security roles and responsibilities 10 |
| Decision rights | The written list of decisions the role may take alone, take jointly, recommend, or must escalate. Anything absent from the list is escalated by default. | Method, against clause 5.3 as above |
| The three lines | Regulation (EU) 2022/2554 has financial entities other than microenterprises assign ICT risk management and oversight to a control function with an appropriate level of independence. It also segregates ICT risk management, control and internal audit functions, following either the three lines of defence model or an internal model for risk management and control. | Regulation (EU) 2022/2554 Art. 6(4) 11 |
| Interested parties | The parties whose requirements the unit must satisfy, each recorded with its own requirement. Clause 4.2 is Understanding the needs and expectations of interested parties. | ISO/IEC 27001:2022 clause 4.2 12 |
3. The method — numbered steps, each with input, activity, output and owner
Nine steps. The first three settle whether the role exists and what it may decide. The next three give it a rhythm and its interfaces. The last three cover reporting, staffing and measures.
3.1 Decide whether the role is needed
The role is an expensive answer to a coordination problem. Where the security function already reaches every decision, it adds a hop and removes nothing. Four questions settle it, and three affirmative answers are usually enough.
Size and distance: how many decisions with security consequences are taken each month outside the central function's sight. Regulatory reach: whether more than one instrument applies across different parts of the organisation. Unit count: how many groupings have their own change pipeline and supplier base. Decision latency: how long a unit waits for a security answer, from question to recorded decision.
- Input: organisation chart; change and procurement volumes per unit; the instruments in scope; a sample of security questions with their response times.
- Activity: score the units against the four questions; record current decision latency; decide, and write the reason down; where the answer is no, name the compensating mechanism.
- Output: role decision record, one page, carrying the four measures and the decision.
- Owner: the head of the security function proposes; top management decides.
3.2 Write the mandate
Control 5.2 of ISO/IEC 27002:2022 asks that information security roles and responsibilities are defined and allocated according to the organisation's needs. Each area of responsibility is defined, documented and communicated, and authorisation levels are documented 10.
Write four things, and refuse to publish without them. Decision rights, as a table of decisions against four verbs: decides, decides jointly, recommends, escalates. The escalation path, naming the receiving role and the maximum time before an unanswered escalation moves up. Both reporting lines: the line that appraises the role, and the line that receives its risk reporting. And an explicit list of what the role does not own — usually policy authorship, control operation, and acceptance of risk belonging to a unit head.
CSF 2.0 states the outcome at GV.RR-02, where roles, responsibilities and authorities for cybersecurity risk management are established, communicated, understood and enforced 13. Resourcing is a separate outcome at GV.RR-03 14.
- Input: the role decision record; the unit list; the existing delegation of authority; the risk acceptance criteria in force.
- Activity: draft the decision-rights table; agree the escalation path and its clock; fix both reporting lines; write the exclusions; obtain two signatures on one page.
- Output: BISO charter carrying a decision-rights map, dated and signed by both parties.
- Owner: the security function drafts; the unit head and top management approve.
The role advises on treatment and does not accept residual risk for the unit. And it does not audit what it designed: control 5.3 lists designing, auditing and assuring information security controls among the activities that can require segregation 15.
3.3 Choose a placement model, and state the trade-off
Three placements recur. Each buys something and costs something, and the cost is structural rather than a matter of execution.
| Model | Reporting line | What it buys | What it costs |
|---|---|---|---|
| Embedded | Appraised by the unit; risk reporting to the security function | Earliest sight of decisions; credibility inside the unit; short decision latency | Capture: the role tends to adopt the unit's appetite and stop escalating |
| Matrixed | Appraised by the security function; assigned to the unit | Consistent judgement across units; easier calibration of risk criteria | Slower answers; the role reads as an outsider and can get routed around |
| Hub | A central pool serving units on rotation or on demand | Scales to many small units; resilient to departures; even coverage | Weakest unit context; relationships tend to restart at each rotation |
State the choice and its cost in the charter. Where the sector prescribes a shape, the prescription wins. Regulation (EU) 2022/2554 has the management body set clear roles and responsibilities for all ICT-related functions, with governance arrangements for communication, cooperation and coordination 16. Read with Article 6(4), that limits how far an embedded role can also be the independent one.
- Input: the charter draft; the unit list with headcount and change volume; the sector's requirements on independence.
- Activity: select the model per unit rather than for the whole organisation; write down the trade-off accepted; record the compensating measure for it.
- Output: placement record per unit, inside the charter.
- Owner: the security function proposes; top management approves.
3.4 Give the role an operating rhythm
A mandate without a calendar becomes a mailbox. The rhythm is the set of points where the role is present by default, so its absence is what has to be explained.
The first is business planning, where the unit's objectives are set and security objectives can be attached to them. Clause 6.2 is Information security objectives and planning to achieve them 17. Then change gates, where the security question is asked before design is fixed; risk reviews, where entries are re-scored and overdue treatment is challenged; and incidents and supplier events, where the role supplies business context.
Control 5.8 of ISO/IEC 27002:2022 asks that information security is integrated into project management, with risks assessed and treated early and periodically through the life cycle 18. Responsibilities and authorities for project security are allocated to specified roles, with stage follow-up by a body such as the project steering committee.
- Input: the unit's planning calendar; the change board schedule; the risk review cadence; the incident and supplier processes.
- Activity: place the role on each calendar as a standing participant; define what it brings and takes away; agree the monthly measures; publish the calendar.
- Output: operating calendar; unit measure set with definitions and reporting dates.
- Owner: the role owns the calendar; the unit head owns attendance.
Measurement makes the rhythm visible, and clause 9.1 is Monitoring, measurement, analysis and evaluation 19. Attendance holds because management makes it hold: control 5.4 has management require all personnel to apply information security in line with the policy and procedures 20.
3.5 Wire the interfaces
The role's value sits in four interfaces, each with a named counterpart and a named artefact.
The risk register is the first. Unit entries are raised, owned and re-scored in the unit, and roll up unchanged into the organisation's register; the method is in Risk registers people actually trust. The role makes sure each entry has an owner who can accept it.
Control owners are the second. The role knows which control operators sit inside the unit and which sit in a shared function. Where the operator is shared, the unit still carries the risk.
The incident process is the third. Central response handles containment and recovery; the role supplies impact framing, customer and regulatory context, and the business decision when a trade-off is unavoidable.
Supplier assurance is the fourth, and sector law is specific here. Regulation (EU) 2022/2554 has financial entities other than microenterprises establish a role to monitor arrangements concluded with ICT third-party service providers. The alternative is a designated member of senior management responsible for overseeing the related risk exposure and documentation 21. CSF 2.0 states the same at GV.SC-02, where supplier, customer and partner roles are established, communicated and coordinated 22. The lifecycle method is in The third-party risk lifecycle.
- Input: the organisation's risk register; the control inventory with operators; the incident process; the supplier register.
- Activity: name the counterpart for each interface; agree the artefact that crosses it and its cadence; record unit decisions in the register the central function reads.
- Output: interface map, one page per interface, inside the charter.
- Owner: the role maintains the map; each counterpart confirms their side.
3.6 Report upward without translating twice
Two audiences read the same underlying data. The unit head needs the exposure their own decisions created; top management needs the organisation's position, with the units that differ named.
Clause 9.3 is management review, with 9.3.2 inputs and 9.3.3 results 2. Unit-level reporting fills the input pack with something other than the security function's own opinion. Results are decisions rather than observations 23. CSF 2.0 closes the loop at GV.OV-03, where risk management performance is evaluated and reviewed for adjustments needed 24.
The board-facing view is in Board reporting for security. Where the unit view and the board view disagree, the disagreement is the finding.
- Input: the unit measure set; register entries with owners; open exceptions and expiry dates; incident and supplier events in the period.
- Activity: publish the unit pack on a fixed date; feed the same figures into the review input pack without re-cutting them; record decisions with owners and dates.
- Output: unit risk report; management review input contribution; decisions in the review record.
- Owner: the role produces the unit pack; the security function assembles the review input.
3.7 Staff the role for competence, not for the certificate list
Clause 7.2 is Competence and clause 7.3 is Awareness 25 26. Control 5.2 adds that a person taking a specific security role should be competent in the knowledge and skills that role requires 10.
The skills mix is the requirement; a qualification evidences part of it and never the whole. Four capabilities carry the role.
-
Reading the unit's business model well enough to price a security trade-off in the unit's own terms.
-
Risk framing: turning a technical finding into a stated exposure with an owner and an acceptance decision.
-
Standards fluency across the instruments in the unit's scope, at clause level, without a specialist alongside.
-
Holding a position under commercial pressure, and knowing when to escalate rather than absorb.
-
Input: the charter; the unit's instrument list; the current skills inventory.
-
Activity: define the capability profile; assess against it; record gaps with development actions and dates; re-assess on a fixed cycle.
-
Output: capability profile; competence records per holder.
-
Owner: the security function owns the profile; the appraising line owns the records.
3.8 Measure whether the function is working
Three measures separate a working role from a title.
Decision latency: elapsed time from a security question raised in the unit to a recorded decision, taken from the sample used in step 3.1. Risk-acceptance records: accepted risks carrying a named unit owner, a date and an expiry, as a proportion of accepted risk in the unit. Findings owned in the unit: the share of assessment findings whose remediation owner sits inside the unit. Where the escalation path is new, add a fourth: escalations raised, and of those, escalations answered within the charter's clock.
CSF 2.0 places the surrounding expectations under Risk Management Strategy. GV.RM-02 has risk appetite and tolerance statements established, communicated and maintained; GV.RM-05 has lines of communication established for cybersecurity risks, including supplier risks 27.
- Input: the decision log; the risk register; the finding register; the escalation log.
- Activity: define each measure once, with its source record; report monthly; review the definitions annually and record any change.
- Output: measure definitions; monthly measure results.
- Owner: the role reports; the security function keeps the definitions stable across units.
3.9 Watch for the three failure shapes
Three shapes recur, each with an indicator that appears before the finding does.
The shadow CISO. The role starts writing policy, running controls and answering the auditor for the unit, and the central function quietly stops covering that unit. The indicator is a policy document whose approver sits in one unit. The correction is the exclusion list in step 3.2, enforced.
The compliance clerk. The role becomes a questionnaire pipeline: evidence requests in, spreadsheets out, no decision anywhere. The indicator is a decision log with no entries beside a rising evidence volume. The correction is to move the role onto the change gate, where decisions are still open.
The escalation that never lands. The path exists on paper, escalations are raised, and nothing comes back. The indicator is the answered-within-clock measure. The correction is a named receiving role and a maximum time, both in the charter, both reported.
Control 5.35 asks that the approach to managing information security and its implementation is reviewed independently, at planned intervals or when significant changes occur 28. Reviewers are independent of the area under review and outside its line of authority.
- Input: the decision log; the escalation log; the policy register; the finding register.
- Activity: test the three indicators each quarter; where one fires, name the correction and a date; include the role's own operation in the independent review programme.
- Output: quarterly indicator check; independent review report covering the role.
- Owner: the security function tests; an independent reviewer covers the role itself.
4. Deliverables
Seven artefacts, each produced by a step above and named as it will be named in the evidence set. Retention periods are organisational choices rather than requirements of any standard.
| Deliverable | Produced by | Format | Retention |
|---|---|---|---|
| Role decision record | Step 3.1 | document | current plus one cycle |
| BISO charter | Step 3.2 | document, dual signature | every version, whole cycle |
| Decision-rights map | Step 3.2 | table inside the charter | every version, whole cycle |
| Placement record per unit | Step 3.3 | table inside the charter | current plus one cycle |
| Operating calendar | Step 3.4 | calendar plus a one-page summary | current period |
| Interface map | Step 3.5 | one page per interface | current plus one cycle |
| Unit risk profile | Steps 3.4 and 3.6 | CSF Organizational Profile | every version, whole cycle |
The unit risk profile is the one artefact with a published shape. A CSF Organizational Profile describes an organisation's current or target cybersecurity posture in terms of the Core's outcomes 29. A Current Profile states the outcomes being achieved and to what extent; a Target Profile states the outcomes selected and prioritised; the gap becomes a prioritised action plan 29.
The interactive companion to this method is the Lab's BISO Guide, running privately, which carries the charter, the register, the control library, assurance and incidents as working surfaces. Templates for the charter and the decision-rights map: template pending.
5. What the auditor or authority will ask
The phrasing follows how an assessor opens a line of enquiry: a request for a record, then a request for the decision behind it.
An assessment that stays with the charter is going well. One that moves to the decision log, then to the unit head, is where a title without a mandate fails.
6. Failure modes and how they surface as findings
Four patterns account for most of the damage. Each is given as the pattern, the wording it produces in a report, and the smallest change that removes it.
The root is the same in all four: authority described in prose instead of written as a list of decisions with owners.
7. Mapping the operating model to the standards
Clause numbers and titles come from the ISO/IEC 27001:2022 contents listing; control numbers and titles from ISO/IEC 27002:2022. Category identifiers come from the CSF 2.0 Core in Appendix A of NIST CSWP 29: GV.OC Organizational Context, GV.RM Risk Management Strategy, GV.RR Roles, Responsibilities, and Authorities, GV.OV Oversight. Requirement text is paraphrased.
| Element | Clause or control | CSF | Evidence sampled | Verified |
|---|---|---|---|---|
| Unit context | 4.1 Understanding the organization and its context | GV.OC | Context record of the unit's issues | 9 |
| Interested parties | 4.2 Understanding the needs and expectations of interested parties | GV.OC | Register rows, each with a named requirement | 12 |
| Mandate and decision rights | 5.3 Organizational roles, responsibilities and authorities | GV.RR | Charter and decision-rights map, signed | 1 |
| Risk ownership | 6.1.2 Information security risk assessment | GV.RM | Register entries with named unit owners | 30 |
| Treatment | 6.1.3 Information security risk treatment | GV.RM | Treatment plan traced to unit entries | 31 |
| Objectives per unit | 6.2 Information security objectives and planning to achieve them | GV.RM | Measure, target and latest result | 17 |
| Competence | 7.2 Competence | GV.RR | Capability profile and per-holder records | 25 |
| Residual risk acceptance | 8.3 Information security risk treatment | GV.RM | Dated acceptance by the entitled owner | 32 |
| Unit measure set | 9.1 Monitoring, measurement, analysis and evaluation | GV.OV | Consecutive monthly results | 19 |
| Reporting upward | 9.3.3 Management review results | GV.OV | Decisions with owners and dates | 23 |
| Findings owned in the unit | 10.2 Nonconformity and corrective action | GV.OV | Finding register with a unit owner | 33 |
| Segregation of assurance | Annex A / ISO/IEC 27002:2022 control 5.3 Segregation of duties | GV.RR | Reviewer independence per review | 15 |
| Independent review | Annex A / ISO/IEC 27002:2022 control 5.35 Independent review of information security | GV.OV | Report on reviewer independence | 28 |
| Management body oversight | Instrument requirement | GV.RR | Approval, oversight and training records | 3 |
| Control-function independence | Instrument requirement | GV.RR | Segregation of risk, control and audit | 11 |
8. Checklist
Each item is observable. "Agreed" is not; a dated signature on a named page is.
Related
- BISO Guide — the Lab's interactive companion to this method.
- Risk registers people actually trust — the register this model feeds.
- The third-party risk lifecycle — the supplier interface.
- Board reporting for security — the upward view.
References
Primary sources only. ISO/IEC 27001:2022 clause titles come from the publisher's own contents listing; ISO/IEC 27002:2022 control numbers and titles from a licensed copy, with requirement text paraphrased.
- ISO/IEC. Information security management systems — Requirements. ISO/IEC 27001:2022. Contents and clause titles read at https://www.iso.org/obp/ui/#iso:std:iso-iec:27001:ed-3:v1:en 34
- ISO/IEC. Information security controls. ISO/IEC 27002:2022. Controls 5.2, 5.3, 5.4, 5.8 and 5.35 read in a licensed copy; catalogue entry at https://www.iso.org/standard/75652.html 35
- National Institute of Standards and Technology. The NIST Cybersecurity Framework (CSF) 2.0. NIST CSWP 29, 26 February 2024. Section 3.1 and Appendix A read at https://doi.org/10.6028/NIST.CSWP.29 36
- European Parliament and Council. Directive (EU) 2022/2555 (NIS 2 Directive). OJ L 333, 27.12.2022, p. 80. Articles 20 and 21 read at https://publications.europa.eu/resource/celex/32022L2555 37
- European Parliament and Council. Regulation (EU) 2022/2554 on digital operational resilience for the financial sector. OJ L 333, 27.12.2022, p. 1. Articles 5 and 6 read at https://publications.europa.eu/resource/celex/32022R2554 38
Cadences, retention periods and measure thresholds above are organisational choices rather than requirements of any standard or instrument named here.
Sources
- 1ISO/IEC 27001:2022 clause 5.3, iso.org/obp · verified 2026-09-03
- 2ISO/IEC 27001:2022 clause 9.3, iso.org/obp · verified 2026-09-03
- 3EU Publications Office CELEX 32022L2555 Art. 20(1) · verified 2026-09-05
- 4EU Publications Office CELEX 32022L2555 Art. 20(2) · verified 2026-09-05
- 5EU Publications Office CELEX 32022L2555 Art. 21(1) · verified 2026-09-05
- 6EU Publications Office CELEX 32022L2555 Art. 21(2) · verified 2026-09-05
- 7NIST CSWP 29 Appendix A GV.RR-01, nvlpubs.nist.gov · verified 2026-09-05
- 8ISO/IEC 27001:2022 clause 5.1, iso.org/obp · verified 2026-09-03
- 9ISO/IEC 27001:2022 clause 4.1, iso.org/obp · verified 2026-09-03
- 10ISO/IEC 27002:2022 control 5.2, licensed copy · verified 2026-09-05
- 11EU Publications Office CELEX 32022R2554 Art. 6(4) · verified 2026-09-05
- 12ISO/IEC 27001:2022 clause 4.2, iso.org/obp · verified 2026-09-03
- 13NIST CSWP 29 Appendix A GV.RR-02, nvlpubs.nist.gov · verified 2026-09-05
- 14NIST CSWP 29 Appendix A GV.RR-03, nvlpubs.nist.gov · verified 2026-09-05
- 15ISO/IEC 27002:2022 control 5.3, licensed copy · verified 2026-09-05
- 16EU Publications Office CELEX 32022R2554 Art. 5(2), point (c) · verified 2026-09-05
- 17ISO/IEC 27001:2022 clause 6.2, iso.org/obp · verified 2026-09-03
- 18ISO/IEC 27002:2022 control 5.8, licensed copy · verified 2026-09-05
- 19ISO/IEC 27001:2022 clause 9.1, iso.org/obp · verified 2026-09-03
- 20ISO/IEC 27002:2022 control 5.4, licensed copy · verified 2026-09-05
- 21EU Publications Office CELEX 32022R2554 Art. 5(3) · verified 2026-09-05
- 22NIST CSWP 29 Appendix A GV.SC-02, nvlpubs.nist.gov · verified 2026-09-05
- 23ISO/IEC 27001:2022 clause 9.3.3, iso.org/obp · verified 2026-09-03
- 24NIST CSWP 29 Appendix A GV.OV-03, nvlpubs.nist.gov · verified 2026-09-05
- 25ISO/IEC 27001:2022 clause 7.2, iso.org/obp · verified 2026-09-03
- 26ISO/IEC 27001:2022 clause 7.3, iso.org/obp · verified 2026-09-03
- 27NIST CSWP 29 Appendix A GV.RM, nvlpubs.nist.gov · verified 2026-09-05
- 28ISO/IEC 27002:2022 control 5.35, licensed copy · verified 2026-09-05
- 29NIST CSWP 29 §3.1, nvlpubs.nist.gov · verified 2026-09-05
- 30ISO/IEC 27001:2022 clause 6.1.2, iso.org/obp · verified 2026-09-03
- 31ISO/IEC 27001:2022 clause 6.1.3, iso.org/obp · verified 2026-09-03
- 32ISO/IEC 27001:2022 clause 8.3, iso.org/obp · verified 2026-09-03
- 33ISO/IEC 27001:2022 clause 10.2, iso.org/obp · verified 2026-09-03
- 34ISO/IEC 27001:2022 contents, iso.org/obp · verified 2026-09-03
- 35ISO/IEC 27002:2022 controls 5.2, 5.3, 5.4, 5.8 and 5.35, licensed copy · verified 2026-09-05
- 36NIST CSWP 29 §3.1 and Appendix A, nvlpubs.nist.gov · verified 2026-09-05
- 37EU Publications Office CELEX 32022L2555 Art. 20 and Art. 21 · verified 2026-09-05
- 38EU Publications Office CELEX 32022R2554 Art. 5 and Art. 6 · verified 2026-09-05
Related
- Board and management reporting for security
Playbook
- IEC 62443 for governance people
Briefing
- Incident governance
Playbook