Quiz Entry - updated: 2026.09.18
Who are the stakeholders of a cyber security architecture, and what makes someone one?
Following the ISO 10006 sense of the word, a stakeholder is a person or group with an interest in a subject or affected by its effects — which for cyber security architecture means five distinct camps, not just "the security team".
* Five camps, not one security team — and being affected is enough to make someone a stakeholder. *
| Camp | Who | Why they are in |
|---|---|---|
| Client role and risk bearers | Management, the business units (Fachbereiche) | They own the risk and commission the changes |
| Users of cyber systems | Employees, partners, customers | They live with the result — and bypass it if it hurts |
| Areas with a security mandate | Information security (CISO), IT security, risk management | It is their job; they set requirements and implement them |
| Audit and control functions | Auditors, financial auditors, certifiers | They must be able to assess the construction |
| Operating and changing cyber systems | IT and OT operations, network administration, developers, projects | They implement and continuously alter the thing |
Two takeaways that are easy to miss:
- Being a stakeholder is not the same as being interested. The definition includes everyone affected, which is exactly why users and operations count even when they never asked for a say. Ignoring an affected group does not remove them; it just guarantees the design meets them as resistance rather than as input.
- The list is a checklist for your own work. Before a design review, run the five camps: have I got the risk owner, the people who will use it, the people who must justify it, the people who must audit it, and the people who must run it?
Go deeper:
Wikipedia — Stakeholder (corporate) — the general corporate definition this borrows, with the primary/secondary split.