Information security coordinator
Also known as: security coordinator
The person who keeps an organisation's day-to-day security work organised, tracked and reported to management.
Draft - this entry has not been reviewed yet.
Formal
A role that runs the security programme in practice - keeping policies and the risk picture up to date, following up on controls and incidents, and linking IT, suppliers and management - often as the owner of the ISMS.
In plain English
Like a wedding planner - they do not cook, play music or take photos, but they make sure everyone who does shows up on time and knows the plan.
In practice
Every quarter the coordinator at a Danish university college collects status from the IT department and HR, updates the risk list and brings three decisions the management team needs to make.
Why it matters
Without one person holding the threads, security tasks get dropped between departments and management loses sight of where the organisation stands.
Technical deep dive
The role has no single legal definition; it is the practical answer to ISO/IEC 27001:2022 clause 5.3, which requires top management to assign responsibility and authority for ensuring that the ISMS conforms to the standard and for reporting ISMS performance to top management. Annex A control 5.2 (information security roles and responsibilities) requires those roles to be defined and allocated, and 5.4 (management responsibilities) requires managers to make staff apply security in line with policy. In the Danish public sector, where state institutions have been required to work according to ISO 27001 since 2016, "informationssikkerhedskoordinator" is a common title for the person who operates the ISMS on behalf of the management, often reporting to a security committee or the director.
The recurring deliverables map closely to the standard. The coordinator maintains the policy set and the documented information required by 7.5, runs the risk assessment cycle (6.1.2) and keeps the risk treatment plan and Statement of Applicability current (6.1.3), tracks the information security objectives and their measurement (6.2 and 9.1), organises internal audits (9.2) without auditing their own work, and prepares management review (9.3). The inputs to management review in 9.3.2 give a ready-made agenda: status of previous actions, changes in internal and external issues and in interested parties' needs, trends in nonconformities, monitoring results, audit results and objectives, feedback from interested parties, results of risk assessment and status of the treatment plan, and opportunities for improvement.
The role coordinates rather than executes. Technical controls are operated by IT operations or suppliers, HR owns screening and onboarding and offboarding (Annex A 6.1-6.5), and procurement owns contract terms (5.19-5.22). The coordinator's leverage comes from mandate and reporting lines, not from administrative privileges; segregation of duties (Annex A 5.3) argues against the coordinator also being the sole system administrator who approves their own changes. In incidents, the coordinator typically acts as incident manager or liaison, assembling facts for NIS2 Art. 23 notifications or GDPR Art. 33 notifications while technical responders contain the event.
The role is easily confused with neighbours. A CISO is an executive owning security strategy and budget; in smaller organisations one person may hold both titles, but the coordinator role alone rarely carries decision authority over budget or risk acceptance, which remains with risk owners and management, and under NIS2 Art. 20 accountability stays with the management body. A data protection officer under GDPR Arts. 37-39 must be independent, may not receive instructions on the performance of DPO tasks and must avoid conflicts of interest, so combining DPO and security coordinator roles needs careful assessment. A compliance and risk coordinator focuses on mapping requirements and evidence; the information security coordinator runs the whole programme day to day.
What to learn first
Everything this builds on, foundations first.
- CIA triad
- →Security policy
- →Threat
- →Asset
- →Vulnerability
- →Impact
- →Likelihood
- →Risk
- →Risk management
- →Information security management system (ISMS)
- →Information security coordinator
Relationships
- A kind of
- Grey roles
- Don't confuse with
- Compliance and risk coordinator
- Used with
- Risk managementSecurity policy
Sources & further reading
Standards & official texts
- ISO/IEC 27001:2022 (clause 5.3 - Organizational roles, responsibilities and authorities)
Course material
- Cyber Security Fast Track - Kursuskompendium, Kursistens udbytte
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Mentioned in
Check yourself
Loading…