Skip to main content
Category: Governance Roles

Information System Security Manager

Also known as: ISSM, Information Systems Security Manager
Simply put

An Information System Security Manager (ISSM) is the person responsible for the cybersecurity of a program, organization, system, or enclave. Generally, the ISSM works at a more strategic level than the Information System Security Officer (ISSO), setting security policy and managing risk across the organization rather than focusing solely on day-to-day operations. Readers should confirm specific duties against their applicable agency or program guidance, as exact responsibilities vary.

Formal definition

The Information System Security Manager (ISSM) is the individual responsible for the cybersecurity of a program, organization, system, or enclave. In most implementations the ISSM defines, implements, and monitors information systems security policy and manages risk at the enterprise level, serving as the strategic counterpart to the ISSO's more operational, system-level focus. Precise authorities, reporting relationships, and delineation between ISSM and ISSO duties are established by the governing agency, program, or accreditation framework and should be verified against current authoritative sources; this entry does not address implementation, contractual, or clearance-specific requirements.

Why it matters

The Information System Security Manager occupies a pivotal position in the governance of defense and public sector information systems because accountability for cybersecurity has to reside with a clearly identified individual rather than being diffused across a team. When the ISSM role is well defined, an organization has a strategic focal point for setting security policy, managing risk across a program or enclave, and coordinating with authorizing officials and operational staff. When the role is absent, ambiguous, or conflated with more operational functions, gaps in accountability can emerge that undermine an organization's overall security posture.

Understanding the ISSM role also matters because it is frequently confused with the Information System Security Officer (ISSO). The distinction is not merely titular: as reflected in the evidence, the ISSM generally functions as the strategic counterpart to the ISSO's more operational, system-level focus, defining, implementing, and monitoring security policy and managing risk at the enterprise level. Treating the two roles as interchangeable can leave either strategic risk management or day-to-day operational security under-served. Readers should note, however, that the precise delineation of duties between the ISSM and ISSO is established by the governing agency, program, or accreditation framework and varies accordingly.

It is important to distinguish the ISSM's responsibility for cybersecurity from any assumption that assigning the role guarantees a secure or compliant system. The ISSM sets and monitors policy and manages risk, but compliance with a control baseline and genuine security are not the same thing, and neither is achieved simply by naming an individual to the position. Exact authorities, reporting relationships, and clearance or contractual requirements should always be verified against current authoritative sources for the applicable agency or program.

Who it's relevant to

Information System Security Managers and prospective ISSMs
Individuals holding or preparing for the ISSM role need a clear understanding that the position generally involves setting security policy, managing risk at the enterprise level, and serving as the strategic counterpart to operational security staff. Because exact duties vary, ISSMs should confirm their specific authorities and responsibilities against their applicable agency or program guidance and consult available role-based resources such as the CDSE ISSM toolkit.
Information System Security Officers (ISSOs)
ISSOs work alongside ISSMs and need to understand the distinction between the two roles. The ISSM generally operates at a strategic, policy-setting, and enterprise risk level, while the ISSO focuses on more operational, system-level security. Confusing or conflating the two can leave either strategic or operational responsibilities under-served, so the delineation should be verified against the governing framework.
Authorizing officials and program leadership
Those with accountability for authorizing systems and overseeing programs rely on a clearly identified ISSM as a focal point for security policy and risk management. Leadership should recognize that assigning an ISSM does not by itself guarantee a secure or compliant system, and should ensure the role's authorities and reporting relationships are clearly established within their agency or program.
Compliance officers and auditors
Compliance and audit personnel evaluating security governance need to confirm that the ISSM role is defined, staffed, and exercised consistently with the organization's applicable framework. Because responsibilities and the ISSM/ISSO boundary vary by agency, program, or accreditation framework, reviewers should assess the role against current authoritative sources rather than a single generic definition.

Inside ISSM

Role Definition
The ISSM is the individual responsible for maintaining the appropriate operational security posture for an information system or program. Under the DoD Risk Management Framework (RMF), the role is generally described in DoD and CNSS guidance, though specific responsibilities may be tailored by the sponsoring organization or component.
Security Documentation Responsibilities
The ISSM typically develops and maintains security authorization documentation, such as the System Security Plan (SSP) and associated artifacts, coordinating with system owners and the authorizing official (AO). Exact documentation sets vary by agency, impact level, and the applicable revision of governing guidance.
Relationship to Governance Roles
The ISSM operates within a structure that generally includes the Authorizing Official (AO), the Information System Security Officer (ISSO), and system or program owners. The ISSM commonly oversees or supervises one or more ISSOs, though reporting lines depend on organizational structure.
Continuous Monitoring Involvement
The ISSM generally supports ongoing assessment and continuous monitoring activities that inform whether an Authority to Operate (ATO) remains valid, since an ATO is time-bound and subject to continued oversight rather than permanent.
Scope of Applicability
The ISSM role as commonly referenced applies within DoD and national security system contexts under the RMF and related CNSS guidance. Analogous roles may exist for federal civilian systems under FISMA or classified environments under the NISPOM, but titles, authorities, and duties can differ and should be confirmed against the governing publication for the specific environment.

Common questions

Answers to the questions practitioners most commonly ask about ISSM.

Is the ISSM the same role as the ISSO?
No. Although the titles are often used loosely and responsibilities can overlap depending on organizational structure, the Information System Security Manager (ISSM) and the Information System Security Officer (ISSO) are generally treated as distinct roles. In most DoD RMF implementations, the ISSM has a broader, program- or organization-level responsibility for the security posture of information systems, while the ISSO typically supports the day-to-day security of a specific system or set of systems. Exact scope, reporting lines, and delegation vary by agency and by how the organization tailors role definitions, so readers should confirm against their governing policy and the applicable authoritative text.
Does the ISSM grant the Authority to Operate (ATO)?
No. The ISSM does not grant an ATO. Under the RMF, the authorization decision generally rests with the Authorizing Official (AO), who is the senior official accepting risk on behalf of the organization. The ISSM typically supports the authorization process, helps prepare and maintain security documentation, and advises on risk, but authorization and assessment are distinct functions. It is also worth noting that an ATO is time-bound and subject to continuous monitoring rather than permanent. Confirm specific decision authorities and delegations against your current governing policy.
Where do the ISSM's responsibilities come from, and how should we document them?
ISSM responsibilities are generally anchored in the organization's governing security policy and role definitions, which in DoD contexts are typically framed within the RMF. Because the precise duties, appointment process, and required qualifications can vary by agency and by tailoring, organizations commonly document ISSM assignments through a formal appointment or designation and describe responsibilities in security plans and internal policy. Verify the required elements, formatting, and approving authority against your current authoritative sources rather than assuming a standard template applies.
How does the ISSM interact with the Authorizing Official and the ISSO during authorization?
In most implementations, the ISSM serves as a coordinating point between technical and management functions, supporting the ISSO's system-level security activities and providing the AO with information needed for a risk-based authorization decision. The ISSM generally helps ensure that security documentation is complete and current, but the AO retains the authorization decision and any assessment activities are handled as a separate function. Specific interaction models and delegations differ across organizations, so confirm the workflow defined in your governing policy.
What is the ISSM's role in continuous monitoring after a system is authorized?
Because authorization is time-bound and subject to ongoing oversight, the ISSM generally has continuing responsibilities after an ATO is issued rather than only during the initial authorization. These typically include supporting the continuous monitoring program, helping track the security posture of systems over time, and coordinating updates to documentation as conditions change. The exact scope of continuous monitoring duties depends on organizational tailoring and applicable policy, which should be confirmed against current authoritative guidance.
Should the ISSM treat compliance with a control baseline as equivalent to system security?
No. Compliance and security are related but not the same, and an experienced ISSM generally distinguishes between demonstrating that controls are implemented and confirming that the system's actual risk posture is acceptable. Meeting a control baseline supports authorization and audit needs, but it does not by itself guarantee security. The ISSM's role commonly includes advising on residual risk rather than treating documented compliance as the end goal. Specific expectations vary by organization and should be verified against governing policy.

Common misconceptions

The ISSM and ISSO are interchangeable titles for the same role.
They are distinct roles within the RMF governance structure. The ISSM generally holds broader program- or system-level security management responsibility and may oversee one or more ISSOs, whose duties are typically more focused on day-to-day implementation. Specific delineation varies by organization, so verify against applicable DoD and CNSS guidance.
Once the ISSM supports issuance of an ATO, the system's authorization is settled and requires no further action.
An ATO is time-bound and remains subject to continuous monitoring. The ISSM generally has ongoing responsibilities to maintain the security posture and support the reassessment activities that determine whether authorization remains valid.
An ISSM ensuring compliance means the system is secure.
Compliance and security are not equivalent. Satisfying documentation and control requirements does not by itself guarantee a secure operational posture, and the ISSM's compliance activities should be understood as one part of broader risk management rather than a guarantee of security.

Best practices

Clearly document the division of responsibilities between the ISSM, ISSOs, system owners, and the authorizing official to avoid gaps or overlaps in accountability, and align these definitions with the applicable DoD and CNSS guidance for your environment.
Treat the ATO as a time-bound authorization by maintaining active continuous monitoring processes rather than assuming authorization persists indefinitely.
Keep the System Security Plan and associated security documentation current, updating artifacts as system configurations, controls, or governing guidance revisions change.
Confirm the specific role authorities and duties against the governing publication for your applicable environment, since ISSM responsibilities can be tailored by component or program and may differ across DoD, federal civilian, and classified contexts.
Distinguish compliance activities from security outcomes, and support risk-based decision-making by the authorizing official rather than treating documented compliance as proof of a secure posture.
Coordinate closely with ISSOs and system owners to ensure operational security activities are consistently reflected in authorization and continuous monitoring records.