LOGBOOK

HELP

Quiz Entry - updated: 2026.09.18

Who are the stakeholders of a cyber security architecture, and what makes someone one?

Following the ISO 10006 sense of the word, a stakeholder is a person or group with an interest in a subject or affected by its effects — which for cyber security architecture means five distinct camps, not just "the security team".

The five stakeholder camps around a security architecture

* Five camps, not one security team — and being affected is enough to make someone a stakeholder. *

Camp Who Why they are in
Client role and risk bearers Management, the business units (Fachbereiche) They own the risk and commission the changes
Users of cyber systems Employees, partners, customers They live with the result — and bypass it if it hurts
Areas with a security mandate Information security (CISO), IT security, risk management It is their job; they set requirements and implement them
Audit and control functions Auditors, financial auditors, certifiers They must be able to assess the construction
Operating and changing cyber systems IT and OT operations, network administration, developers, projects They implement and continuously alter the thing

Two takeaways that are easy to miss:

  • Being a stakeholder is not the same as being interested. The definition includes everyone affected, which is exactly why users and operations count even when they never asked for a say. Ignoring an affected group does not remove them; it just guarantees the design meets them as resistance rather than as input.
  • The list is a checklist for your own work. Before a design review, run the five camps: have I got the risk owner, the people who will use it, the people who must justify it, the people who must audit it, and the people who must run it?

Go deeper:

From Quiz: CSARCH / What Cyber Security Architecture Is, and Who It Is For | Updated: Sep 18, 2026