Skip to content
atlas

Information security coordinator

Also known as: security coordinator

The person who keeps an organisation's day-to-day security work organised, tracked and reported to management.

Draft - this entry has not been reviewed yet.

Formal

A role that runs the security programme in practice - keeping policies and the risk picture up to date, following up on controls and incidents, and linking IT, suppliers and management - often as the owner of the ISMS.

In plain English

Like a wedding planner - they do not cook, play music or take photos, but they make sure everyone who does shows up on time and knows the plan.

In practice

Every quarter the coordinator at a Danish university college collects status from the IT department and HR, updates the risk list and brings three decisions the management team needs to make.

Why it matters

Without one person holding the threads, security tasks get dropped between departments and management loses sight of where the organisation stands.

Technical deep dive

The role has no single legal definition; it is the practical answer to ISO/IEC 27001:2022 clause 5.3, which requires top management to assign responsibility and authority for ensuring that the ISMS conforms to the standard and for reporting ISMS performance to top management. Annex A control 5.2 (information security roles and responsibilities) requires those roles to be defined and allocated, and 5.4 (management responsibilities) requires managers to make staff apply security in line with policy. In the Danish public sector, where state institutions have been required to work according to ISO 27001 since 2016, "informationssikkerhedskoordinator" is a common title for the person who operates the ISMS on behalf of the management, often reporting to a security committee or the director.

The recurring deliverables map closely to the standard. The coordinator maintains the policy set and the documented information required by 7.5, runs the risk assessment cycle (6.1.2) and keeps the risk treatment plan and Statement of Applicability current (6.1.3), tracks the information security objectives and their measurement (6.2 and 9.1), organises internal audits (9.2) without auditing their own work, and prepares management review (9.3). The inputs to management review in 9.3.2 give a ready-made agenda: status of previous actions, changes in internal and external issues and in interested parties' needs, trends in nonconformities, monitoring results, audit results and objectives, feedback from interested parties, results of risk assessment and status of the treatment plan, and opportunities for improvement.

The role coordinates rather than executes. Technical controls are operated by IT operations or suppliers, HR owns screening and onboarding and offboarding (Annex A 6.1-6.5), and procurement owns contract terms (5.19-5.22). The coordinator's leverage comes from mandate and reporting lines, not from administrative privileges; segregation of duties (Annex A 5.3) argues against the coordinator also being the sole system administrator who approves their own changes. In incidents, the coordinator typically acts as incident manager or liaison, assembling facts for NIS2 Art. 23 notifications or GDPR Art. 33 notifications while technical responders contain the event.

The role is easily confused with neighbours. A CISO is an executive owning security strategy and budget; in smaller organisations one person may hold both titles, but the coordinator role alone rarely carries decision authority over budget or risk acceptance, which remains with risk owners and management, and under NIS2 Art. 20 accountability stays with the management body. A data protection officer under GDPR Arts. 37-39 must be independent, may not receive instructions on the performance of DPO tasks and must avoid conflicts of interest, so combining DPO and security coordinator roles needs careful assessment. A compliance and risk coordinator focuses on mapping requirements and evidence; the information security coordinator runs the whole programme day to day.

What to learn first

Everything this builds on, foundations first.

  1. CIA triad
  2. →Security policy
  3. →Threat
  4. →Asset
  5. →Vulnerability
  6. →Impact
  7. →Likelihood
  8. →Risk
  9. →Risk management
  10. →Information security management system (ISMS)
  11. →Information security coordinator

Relationships

A kind of
Grey roles

Sources & further reading

Standards & official texts

  • ISO/IEC 27001:2022 (clause 5.3 - Organizational roles, responsibilities and authorities)

Course material

  • Cyber Security Fast Track - Kursuskompendium, Kursistens udbytte

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Mentioned in

Check yourself

Loading…

Atlas is in beta.