LOGBOOK

HELP

Quiz Entry - updated: 2026.09.18

What does the information security function (CISO and staff) contribute to a cyber security architecture?

The two questions everything else hangs from — what must be protected, and how much risk is bearable — and with them the justification for every security measure.

The remit of a CISO and their staff covers:

  • Security policies and security requirements — the binding rules the organisation works to.
  • Protection goals and risk analyses — what each asset needs (confidentiality, integrity, availability) and what threatens it.
  • Realising an ISMS, an Information Security Management System: the management system that makes security a governed, repeating process (identify assets, assess risks, decide treatment, implement, check, improve) rather than a project that ends.
  • Working on the formal basis of the ISO/IEC 27000 family — 27001 being the certifiable standard for an ISMS and 27002 the control catalogue.

For the architect, this function is the source of two things that cannot be derived technically:

  1. Requirements. "This data is confidential to level X" is not a fact you can read off a network diagram.
  2. The justification (Begründung) for measures. This is the underrated half. Every control costs money and friction, and is therefore challenged. An architect who can answer "because this system processes data whose loss is rated as a major risk, and the risk owner accepted only up to this level" wins arguments that an architect citing best practice loses.

Tip: information security says what and why, IT security says how, architecture is how it all fits together. If you cannot name which of the three you are doing in a given meeting, that is usually the reason the meeting is going badly.

Go deeper:

From Quiz: CSARCH / What Cyber Security Architecture Is, and Who It Is For | Updated: Sep 18, 2026