---
title: A brief insight into the responsibilities of an Information Security Manager (ISM)
description: Information security is a very broad field. It spans across misuse of enterprise information, disruption, unauthorised access, and covers both physical aspects of security as well as cyber security.
image: https://csacyber.com/hubfs/ism.png
---

[Skip to content](https://csacyber.com/blog/a-brief-insight-into-the-responsibilities-of-an-information-security-manager-ism#main-content)

[![CSA Cyber - Cyber Security Solutions to Protect your People](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Full%20Logo.png?width=300&height=108&name=CSA%20Cyber%20Logo%20FNL_Full%20Logo.png "CSA Cyber - Cyber Security Solutions to Protect your People")](https://csacyber.com/)

- Services 
    - [Offensive Security Services](https://csacyber.com/offensive-security-services) 
          - [Penetration Testing](https://csacyber.com/penetration-testing)
          - [Red Teaming and attack simulations](https://csacyber.com/offensive-security-services#red-teaming)
          - [Continuous testing](https://csacyber.com/offensive-security-services#continuous-assurance)
          - [Managed offensive security](https://csacyber.com/offensive-security-services#managed-offensive)
    - [Consultancy Services](https://csacyber.com/cyber-consultancy-services) 
          - [Frameworks & assessments](https://csacyber.com/cyber-consultancy-services/frameworks-and-assessments)
          - [Data protection](https://csacyber.com/cyber-consultancy-services#data-protection)
          - [Virtual leadership](https://csacyber.com/cyber-consultancy-services#virtual-leadership)
          - [Technical security consulting](https://csacyber.com/cyber-consultancy-services#technical-consultancy)
          - [Governance, Risk & Compliance (GRC)](https://csacyber.com/cyber-consultancy-services/governance-risk-and-compliance-services)
    - [Extended Managed Security Services](https://csacyber.com/extended-managed-security-services) 
          - [Microsoft Sentinel SIEM](https://csacyber.com/extended-managed-security-services#microsoft-sentinel)
          - [SOC services](https://csacyber.com/extended-managed-security-services#soc-services)
          - [SentinelOne Endpoint Detection & Response (EDR)](https://csacyber.com/extended-managed-security-services#cyber-helpdesk)
    - [Incident Response Services](https://csacyber.com/incident-response-services) 
          - [Emergency Incident Response](https://csacyber.com/urgent/emergency-incident-response)
          - [Incident Response Retainer](https://csacyber.com/incident-response-services)
          - [Cyber Incident Readiness & Response Planning](https://csacyber.com/incident-response-services)
          - [Tabletop Exercises & Live-Range Engagements](https://csacyber.com/incident-response-services)
    - [Specialist Security Services](https://csacyber.com/specialist-services) 
          - [AI Security](https://csacyber.com/cyber-services-for-ai)
          - [Operational Technology (OT)](https://csacyber.com/specialist-services#operational-technology)
          - [Cyber security for Private Equity](https://csacyber.com/specialist-services#mergers-and-acquisitions)
          - [Cyber training and education](https://csacyber.com/specialist-services#training-and-education)
          - [Virtual leadership](https://csacyber.com/specialist-services#leadership)
    - [Cyber Technologies](https://csacyber.com/cyber-technologies) 
          - [SentinelOne Endpoint Detection & Response (EDR)](https://csacyber.com/cyber-technologies#sentinelone)
          - [AppGuard Endpoint & Server Zero Trust Protection](https://csacyber.com/cyber-technologies#appguard)
          - [Qualys Vulnerability Management as a Service (VMaaS)](https://csacyber.com/cyber-technologies#qualys-vmaas)
          - [Lookout Mobile Device Protection](https://csacyber.com/cyber-technologies#lookout)
          - [ThreatER DNS Protection](https://csacyber.com/cyber-technologies#threater-dns)
          - [Cyber Security Awareness & Training platform](https://csacyber.com/cyber-technologies#boxphish)
- [About](https://csacyber.com/about-us) 
    - [Careers](https://csacyber.com/careers)
    - [Certifications](https://csacyber.com/certifications-and-awards)
- [Blog](https://csacyber.com/blog)
- [Support Centre](https://csacyber.com/support)
- Resources 
    - [Case Studies](https://csacyber.com/case-studies)
    - [Downloads & Reports](https://csacyber.com/downloads-and-reports)
    - [Webinars](https://csacyber.com/webinars)
    - [Partners](https://csacyber.com/partners)
    - [Cyber Bundles (IT MSPs)](https://csacyber.com/cyber-bundles)
- [Contact](https://csacyber.com/contact-us)

- Search Search
  
  Search

 September 16, 2023

 4 min read time

# A brief insight into the responsibilities of an Information Security Manager (ISM)

![Emilio Vancheri](https://app.hubspot.com/settings/avatar/d41d8cd98f00b204e9800998ecf8427e) [Written by: Emilio Vancheri -](https://csacyber.com/blog/author/emilio-vancheri)

[Consultancy](https://csacyber.com/blog/tag/consultancy) 

![](https://csacyber.com/hubfs/ism.png)

Information security is a very broad field. It spans across misuse of enterprise information, disruption, unauthorised access, and covers both physical aspects of security as well as cyber security. Technologies used include endpoint protection and response (EDR), vulnerability management tools, and security information and event management (SIEM) tools. All these areas of security therefore require some form of management- reporting on data generated by the many tools available and suggesting improvements. Overall, these security facets require someone who can provide a holistic view on a company's security and can see it from the various angles it presents.

This is where the role of an Information Security Manager (ISM) becomes necessary.

### What is an Information Security Manager?

To help give a better understanding of the role of an information security manager, here is a breakdown of the typical core responsibilities. These will vary based on the organisation, however, the below are a good baseline:

- General Security Management
- Security Reporting
- Security Documentation
- Security Project Management
- "Bridging the Gap" - Communication skills at technical and managerial levels

**General Security Management:** This includes overseeing general day-to-day security operations and tracking the different areas of security relevant to the organisation. ISM's will routinely review systems like the EDR tool in place, network security systems monitoring network traffic and alerts, and DLP tools tracking user activity related to data sharing. The purpose is to better understand the business's current security posture, and to look for indicators of future cyber security risks.

**Security Reporting:** Security reporting can include many areas. Security incident reporting, weekly and monthly alert reporting and vulnerability reporting are a few of the many reports important to share within your organisation. Through this constant awareness and visibility comes one of the greatest benefits of reporting: encouraging the culture of security. Having security at the forefront and within the minds of your employees is a key performance indicator that any professional in security will share.

**Security Documentation:** Managing your organisation’s security documentation and policies is easily one of your most important tasks as an ISM. These policies and documents will create the foundation for you to build a secure working environment, guiding conversation around the future of security within your organisation and setting the benchmark for any company or external business that you work with. They are also critical to regulation and compliance standards (ISO27001, Cyber Essentials etc..).

**Security Project Management:** Any security-conscious organisation will always be looking to improve and proactively monitor their estate to ensure they are reducing their vulnerabilities as much as possible. This takes the form of regular penetration tests, as well as audits of systems and business processes, to ensure business operation is as secure as it can be. It's the role of an ISM to manage these projects as they will require resources to be aligned internally and externally to ensure they are completed.

**"Bridging the Gap":** The final role is more general in nature, as opposed to the specific roles described previously. ISM's usually sit between the technical IT and security teams, and the less-technical upper management and general staff members. This position is particularly important as it is the role of an ISM to be able to "bridge the gap" by connecting the more technical staff with the less technical staff. The best way to describe this is to use an example: Let's say you have a group of users who prefer to share data through a 3rd party software (e.g. Dropbox) rather than the company's SharePoint site. The security team are advising that users should be using the dedicated SharePoint sites for sharing information as it's more secure and can be tracked. However, the group of users using the 3rd party application don’t want to switch as they are used to using other software, and don’t see the need to switch over to a more secure method. It's the duty of an ISM to explain the importance of the move and to be able to communicate it in terms that all the users will be able to understand. Clearer communication between these two areas increases understanding and awareness of security and will see your organisation better secured.

### What can you do?

Depending on the size of your organisation, having a dedicated ISM within your business may be out of the question when considering available resources. This is where you tend to find the responsibilities of an ISM passed on to other team members (like IT Managers or the Head of Finance), which can both take away from their current roles and lessen the importance of security within the organisation as a result. This is where a Virtual Information Security Manager (vISM) can step in to fill the gap. A vISM is a dedicated ISM who can be contracted to work a specific number of days a year, or by month, to review your security posture, generate reports or assist in policy and document creation. A vISM can be an extension of an existing security or IT team, or can simply be called-on when needed to offer guidance or advice.

### Conclusion

The role of an ISM is essential within a security-conscious organisation. Ranging from areas like vulnerability management to security documentation / policy, ISM's have a responsibility to constantly review the cybersecurity landscape to ensure their organisation is as secure as possible. If an organisation doesn't have the capacity for an ISM full-time, they can opt for a vISM on a day-rate basis to fill the gap and provide a clear insight into what security should look like for your organisation.

If you want to find out more about what a vISM can do for your organisation, or if it would be suitable fit, please [Contact Us](https://csacyber.com/contact-us)

Related Posts

## You may also like this

[Similar Articles](https://csacyber.com/blog)

[![](https://csacyber.com/hs-fs/hubfs/20230510-N1005919-Edit1.jpg?width=624&height=427&name=20230510-N1005919-Edit1.jpg)](https://csacyber.com/blog/fluidone-group-appoints-charly-davis-as-managing-director-of-csa-cyber-to-advance-its-security-first-strategy)

 August 24, 2026

 2 min read

### [FluidOne Group appoints Charly Davis as Managing Director of CSA Cyber to advance its security-first strategy](https://csacyber.com/blog/fluidone-group-appoints-charly-davis-as-managing-director-of-csa-cyber-to-advance-its-security-first-strategy)

 Experienced industry leader joins FluidOne to strengthen integrated cyber, IT and secure networking...

[![CSA Cyber](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Stacked.png?width=40&height=40&name=CSA%20Cyber%20Logo%20FNL_Stacked.png) CSA Cyber](https://csacyber.com/blog/author/csa-cyber)

[![](https://csacyber.com/hs-fs/hubfs/Untitled%20design.jpg?width=624&height=427&name=Untitled%20design.jpg)](https://csacyber.com/blog/csa-cyber-and-fluidone-named-as-suppliers-on-g-cloud-15)

 August 20, 2026

 2 min read

### [CSA Cyber and FluidOne named as suppliers on G-Cloud 15](https://csacyber.com/blog/csa-cyber-and-fluidone-named-as-suppliers-on-g-cloud-15)

 CSA Cyber (CSA), part of the FluidOne Group, has been named as a supplier on Government Commercial...

[![CSA Cyber](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Stacked.png?width=40&height=40&name=CSA%20Cyber%20Logo%20FNL_Stacked.png) CSA Cyber](https://csacyber.com/blog/author/csa-cyber)

[![](https://csacyber.com/hs-fs/hubfs/Engineered%20to%20Endure%20Campaign%20Assets%20(2).png?width=624&height=427&name=Engineered%20to%20Endure%20Campaign%20Assets%20(2).png)](https://csacyber.com/blog/why-organisations-lose-security-visibility-without-realising-it)

 August 20, 2026

 6 min read

### [Why organisations lose security visibility without realising it](https://csacyber.com/blog/why-organisations-lose-security-visibility-without-realising-it)

 Before an organisation can understand risk, maintain control or respond effectively to emerging...

[![CSA Cyber](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Stacked.png?width=40&height=40&name=CSA%20Cyber%20Logo%20FNL_Stacked.png) CSA Cyber](https://csacyber.com/blog/author/csa-cyber)

[![CSA Cyber Logo FNL_Full Logo](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Full%20Logo.png?width=3463&height=1248&name=CSA%20Cyber%20Logo%20FNL_Full%20Logo.png "CSA Cyber Logo FNL_Full Logo")](https://csacyber.com/)

Established in 2013, Cyber Security Associates Limited trading as CSA Cyber provides cyber consultancy and cyber managed services which help to detect, protect and educate against the ever-changing cyber threat. We have built our team from a foundation of Government (ex-Military) and Commercially experienced specialists all holding current and relevant cyber certifications. Today our core services are based around a 24/7 Security Operations Centre (SOC) based in Gloucester.

#### News & Resources

- [Blog](https://csacyber.com/blog)
- [Case Studies](https://csacyber.com/case-studies)
- [Downloads & Reports](https://csacyber.com/downloads-and-reports)
- [Webinars](https://csacyber.com/webinars)
- [Careers](https://csacyber.com/careers)
- [Cyber Bundles (IT MSPs)](https://csacyber.com/cyber-bundles)

#### Quick Links

- [About Us](https://csacyber.com/about-us)
- [Certifications](https://csacyber.com/certifications-and-awards)
- [Our Parent Company](https://www.fluidone.com)
- [Partners](https://csacyber.com/partners)
- [Contact Us](https://csacyber.com/contact-us)
- [Anti Bribery Policy](https://csacyber.com/hubfs/CSAAnti-BriberyPolicy.pdf)
- [Complaints Policy](https://csacyber.com/hubfs/CSAComplaintsPolicy.pdf)
- [Corporate Social Responsibility Policy](https://csacyber.com/hubfs/CSACorporateSocialResponsibilityPolicy.pdf)
- [Slavery and Human Trafficking Statement](https://csacyber.com/hubfs/CSASlaveryandHumanTraffickingStatement.pdf)
- [NCSC CHECK Status Verification](https://www.ncsc.gov.uk/organisation/csa-cyber/check-penetration-testing)
- [CREST Approved Certification Verification](https://www.crest-approved.org/member_companies/csa-cyber/)

#### Contact Information

**United Kingdom - London**

Cyber Security Associates Ltd

5 Hatfields, London, SE1 9PG

 

**United Kingdom - Gloucester**

Cyber Security Associates Ltd

Unit 11, Wheatstone Court, Waterwells Business Park, GL2 2AQ

 

**Phone:** [+44(0) 300 303 4691](tel:03003034691)

**Email:** [hello@csacyber.com](mailto:hello@csacyber.com)

 

**United States of America**

Cyber Security Associates Inc.

6010 W. Spring Creek Pkwy, Plano, Texas, 75024

 

**Phone:** [+1 469 750 1695](tel:14697501695) 

**Email:** [hello@csacyber.com](mailto:hello@csacyber.com)

 

[![trust-pilot](https://csacyber.com/hs-fs/hubfs/trust-pilot.png?width=178&height=104&name=trust-pilot.png)](https://uk.trustpilot.com/review/csa.limited)

 

---

- [Website Terms of Use](https://csacyber.com/website-terms-of-use)
- [Website Privacy Policy](https://csacyber.com/privacy-notice)
- [Website Cookie Policy](https://csacyber.com/cookie-policy)

 Copyright 2026. Cyber Security Associates Ltd [Follow us on Facebook](https://www.facebook.com/CSALIMITED/) [Follow us on LinkedIn](https://www.linkedin.com/company/csa-cyber/) [Follow us on Twitter](https://twitter.com/cybersecurityis) [Follow us on Facebook](https://www.youtube.com/@cybersecurityassociateslim) [Follow us on Facebook](https://www.instagram.com/cybersecurityassociates)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Emilio Vancheri",
    "url" : "https://csacyber.com/blog/author/emilio-vancheri"
  },
  "dateModified" : "2024-12-06T12:07:45.414Z",
  "datePublished" : "2023-09-16T04:00:00.000Z",
  "headline" : "A brief insight into the responsibilities of an Information Security Manager (ISM)",
  "image" : [ "https://csacyber.com/hubfs/ism.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://csacyber.com/blog/a-brief-insight-into-the-responsibilities-of-an-information-security-manager-ism",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://csacyber.com/hubfs/csacyber-logo-black-01.svg"
    },
    "name" : "Cyber Security Associates Ltd"
  }
}
```