Back to insights
Training
What an information security manager actually does
8 July 2025 · 3 min read
An information security manager takes responsibility for overseeing and controlling all aspects of computer security in a business. The job entails planning and carrying out security measures that will protect a business's data and information from deliberate attack, unauthorised access, corruption and theft.
That single sentence covers a wide role. Broken down, the core competencies are:
- Establishing compliance guidelines for the regulations that apply to the business
- Running internal audits and compliance reviews
- Performing gap analysis against frameworks such as ISO 27001, ISO 27002, ISO 27005 and NIST CSF
- Reviewing organisational policies, procedures and guidelines
- Running risk assessments and choosing appropriate remediation
- Identifying vulnerabilities and addressing security weaknesses
- Meeting the regulatory standards that apply — data privacy, GDPR, HIPAA and equivalents
- Keeping staff aware of security policy and process
- Educating staff on information security risk and its legal implications
The last two are easy to underweight next to the technical items, but staff awareness is usually where the gap actually is — most breaches start with a person, not a system.