IT security management

IT security management is the planning, steering and control task through which an organization establishes, reviews and improves information security on an ongoing basis. The German BSI calls it (information) security management and describes it in BSI Standard 200-1 and module ISMS.1; it is carried out through an ISMS. Management bears overall responsibility.

ISMSLast reviewed:

What is IT security management?

IT security management is the leadership task of planning, steering and controlling information security as an ongoing process instead of leaving it to individual measures. The German IT-Grundschutz defines it in module ISMS.1 as the planning, steering and control task required to build and continuously run a well-designed and effective process for establishing information security.

The task is carried out through an ISMS: IT security management is the activity, and the ISMS is the system in which it takes place. How to build an ISMS is described in the guide to implementing an ISMS.

ISO 27001 and the BSI standards describe the same task

IT security management can be run according to ISO/IEC 27001 or the BSI standards of IT-Grundschutz; both routes lead to a certifiable ISMS. BSI Standard 200-1 describes itself as fully compatible with ISO/IEC 27001.

SourceRole for IT security managementCertifiable
ISO/IEC 27001requirements for the ISMS in clauses 4 to 10, plus 93 controls in Annex Ayes
ISO/IEC 27002guidance on implementing the controls in Annex Ano
BSI Standard 200-1general requirements for an ISMSno, foundation
BSI Standard 200-2IT-Grundschutz methodology with basic, core and standard protectionvia ISO 27001 on the basis of IT-Grundschutz
BSI Standard 200-3risk analysis on the basis of IT-Grundschutzno, method
Module ISMS.1, Edition 2023concrete requirements for security managementvia ISO 27001 on the basis of IT-Grundschutz

The BSI is replacing the IT-Grundschutz Compendium with a digital ruleset. During the multi-year transition, IT-Grundschutz with the Compendium in Edition 2023 remains applicable (as of October 2026).

The 4 phases of IT security management

IT security management runs as a cycle of planning, implementation, performance review and improvement. BSI Standard 200-1 calls it the PDCA cycle after the English phase names. The right-hand column shows which clauses of ISO/IEC 27001 govern each phase.

PhaseWhat happensOutputClauses of ISO/IEC 27001
Plananalyze the context, set security objectives and strategy, define the scope, assess riskspolicy, scope, risk assessment, treatment plan4 to 6
Doimplement the security concept and controls, communicate policies, train staffimplemented controls, policies, training records7, 8
Checkcheck whether the controls work and put the result to managementmetrics, review reports, management decisions9
Actfix deficiencies, take corrective action; return to planning after fundamental changescorrective actions, updated concept10

Which topic-specific policies are communicated in the Do phase is shown in the overview of IT security policies.

Risk analysis carries the cycle. Without it, an organization can justify neither which controls it implements nor which residual risks management accepts.

Management bears overall responsibility

The management of the organization is responsible for IT security management and can delegate tasks but not this responsibility. BSI Standard 200-1 sets out three basic rules for this in chapter 7.2. Overall responsibility remains with management, at least one named person coordinates the process, and every employee takes care of security at their own workplace.

RoleTask in IT security managementSource
Managementoverall responsibility, objectives and strategy, resources, approval of the policy, decisions on residual risksBSI Standard 200-1, ch. 7.2; ISMS.1.A1 to A3 and A12; BSI Standard 200-3
Information security officerpromotes and coordinates the security process, reports directly to management where needed, is involved early in major projectsISMS.1.A4; BSI Standard 200-1, ch. 7.2
IS management teamsupports the information security officer in larger organizations on objectives, policy, implementation checks and the training conceptBSI Standard 200-2, ch. 4.5
Employeesknow and apply the security measures that concern their workplaceBSI Standard 200-1, ch. 7.2; ISMS.1.A8

BSI Standard 200-1 recommends organizing the information security officer as a staff unit so that the role has direct access to management. Clause 5.3 of ISO/IEC 27001 requires management to assign responsibilities for the ISMS.

Is IT security management mandatory?

There is no general duty for all companies. Three groups have a statutory or contractual basis:

GroupBasisWhat is required
Essential and important entities under NIS2§ 38(1) of the German BSI Act (BSIG)Management implements the risk management measures under § 30 BSIG and monitors their implementation; under § 38(3) it takes part in training regularly.
Controllers and processors under the GDPRArticle 32(1)(d) GDPRa process for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures
Organizations with an ISO 27001 certificatecertification contractan ISMS with management review, internal audits and continual improvement

The measures under § 30(1) BSIG must be appropriate, proportionate and effective. The review under Article 32(1)(d) GDPR corresponds to the check phase of the cycle.

How much IT security management does a small company need?

A small company needs the same elements with less formality. BSI Standard 200-1 states that the effort for the security process "as a rule depends on the size of the institution".

As an example, the standard names an annual meeting between the managing director and the IT service provider about problems, costs and technical developments. In a small company, such a meeting can already be enough to question the success of the security process. The three basic rules from chapter 7.2 apply there too: management bears overall responsibility, and a named person coordinates the process.

Rizzqo computes implementation status for management

Rizzqo carries the implementation status that management assesses in the check phase as a computed result of finalized answers. Requirements from the held catalogs ISO/IEC 27001 and ISO/IEC 27002 appear on every asset of the matching category. The owner finalizes them there under name and timestamp.

Rizzqo computes the risk assessments linked to the assets with likelihood in percent and impact in euros through a configurable matrix. Measures run as tasks whose planned risk reduction is applied on completion, with optional two-way sync to Jira. Management thus sees which residual risk it carries and which task reduces it.

Browse all entriesBack to top

Frequently asked questions

See compliance run on your real assets

Rizzqo turns framework requirements into owned tasks on the assets you already have, and prices the risk in real money.

Made in GermanyHosted in your countryMulti-framework