A guide to the Information Security Office Body of Knowledge (ISOBOK™)

Defines and describe the core knowledge areas, the skills, deliverables, and techniques that the Information Security Officers require to achieve better security outcomes.

A CONSENSUS-DRIVEN STANDARD FOR THE INFORMATION SECURITY OFFICE


ISOBOK™ is developed through a rigorous consensus-driven standards development process and incorporates the collective wisdom and experience of experts in the field from around the world. It defines the skills and knowledge required by ISO professionals.

  • Contains a description of generally accepted practices for the establishment of Information Security Offices.
  • Community driven and consensus based, continuously updated through iterations.
  • Techniques are transferable with option to modify concepts and best practices for wide range of organizational contexts.
  • Includes the highly valued Reporting Framework.

Knowledge Areas


1. Security Leadership
  • Defines the ISO’s role, competencies, and mindset, including the different types of ISOs.
  • Establishes the security organisation’s structure, charter, and board-level mandate.
  • Aligns with industry standards and frameworks to develop a comprehensive security strategy.
  • Covers setting up budgets, initiating security programs, and embedding the function into enterprise governance.
2. Security Culture
  • Emphasizes that humans are the final line of defense and central to effective security.
  • Promotes a human-centric approach through awareness, training, and behavior-shaping initiatives.
  • Uses phishing simulations, access hygiene practices, and continuous reinforcement to improve behaviors.
  • Encourages a feedback-driven culture of continuous improvement and user engagement.
3. Security Governance
  • Establishes governance through policies, frameworks, ISMS, and the 3 Lines of Defense model.
  • Defines risk management approaches, including qualitative/quantitative methods, tolerance, and appetite.
  • Integrates compliance, audit, and control mechanisms to align security and business risk.
  • Addresses fraud prevention, governance councils, and harmonization between compliance and security.
4. Security Advisory
  • Advises on security trends, frameworks, and standards, supporting strategic and operational decisions.
  • Applies a layered defense model and reviews risks across technology domains.
  • Offers guidance on integrating emerging technologies and securing IT/OT environments.
5. Security Operations
  • Aligns security operations with business goals through a service-based SOC model.
  • Plans and executes incident and crisis management using structured detection and response frameworks.
  • Defines SOC team roles and leverages platforms like SIEM, SOAR, and threat intelligence tools.
6. Security Reporting
  • Delivers tiered reporting for operational, management, and board-level audiences.
  • Ensures regulatory, legal, and external stakeholder reporting meets compliance obligations.
  • Uses KPIs, KRIs, dashboards, and threat intelligence to communicate performance and risk posture.
  • Follows best practices for effective, actionable, and transparent security reporting.

Mapping ISOBOK™ to the Eristotle Information Security Office Competency Model

Eristotle Information Security Office Competency Model ensures a comprehensive development path, from foundational awareness to hands-on execution and strategic foresight, suitable for both technical operators and decision-makers in the corporate information security organization domain.

Foundational Learning

Core principles, structures, and baseline knowledge essential for building a security function.

These areas establish the foundational knowledge required to build and lead a corporate information security function, setting the strategic direction, defining leadership roles, and embedding governance structures.

They cover the essential elements of organizational security architecture, risk oversight, policy frameworks, and alignment with regulatory and business imperatives.

Security Leadership

  • Define the role, mindset, and competencies of the ISO, along with the structure and mandate of the Information Security Organisation.
  • Understand key security frameworks, industry standards, and how to write the Security Charter.

Security Governance

  • Lay the groundwork for governance with the 3 Lines of Defense model, policies, and control structures (e.g., ISMS, frameworks).

Applied Learning

Operational execution, integration of controls, and actionable practices.

This area focuses on developing the human-centric skills and awareness essential for fostering a resilient security environment and influencing secure behaviors across the organization.

Operations builds the operational capabilities required to manage day-to-day security functions, coordinate incident response, and effectively handle large-scale cyber incidents.

Security Culture

  • Emphasize the human element as the final line of defense through awareness, training, and behavioral influence.
  • Implement access hygiene measures (e.g., password policies) and foundational phishing education.
  • Promote a security-first culture using structured education and reinforcement mechanisms.

Security Operations

  • Develop and operate a SOC aligned with business objectives, integrating people, process, and technology.
  • Establish incident detection, classification, alerting, and crisis management capabilities.
  • Leverage platforms such as SIEM, SOAR, and threat intelligence to monitor and respond to threats.

Adaptive Learning

Forward-looking leadership, strategic alignment, and adaptability in complex environments.

This area equips professionals to provide strategic guidance on emerging threats, evolving technologies, and secure integration across business and IT environments. It also develops the capability to deliver clear, risk-informed reporting that supports executive decision-making, regulatory compliance, and stakeholder communication.

Security Advisory

  • Act as a trusted advisor on security trends, layered defenses, and standards integration.
  • Assess risks from emerging technologies, and guide secure IT/OT convergence.
  • Lead adaptive decision-making to keep pace with evolving threat landscapes and governance shifts.

Security Reporting

  • Execute internal and external reporting for senior management, regulators, and stakeholders using KPIs and KRIs.
  • Notifications and regulatory communication obligations towards authorities, suppliers, customers and other stakeholders.

View ALL Information Security Office Related Certifications

A Common Language for The Information Security Office


The Information Security Organisation Body of Knowledge (ISOBOK™) defines the essential skills, structural capabilities, and strategic competencies required for professionals leading enterprise information security functions. It extends beyond foundational security practices to address evolving business needs, regulatory complexity, digital transformation, and organizational resilience including:

  • A conceptual framework that standardizes terminology and principles across the six core domains of corporate information security.
  • Structured knowledge areas that support security leadership and execution across all organizational levels, from day-to-day operations to board-level governance.
  • Six integrated domains that reflect the operational, cultural, strategic, and advisory responsibilities of a mature security function.
  • Coverage of emerging practices and technologies, including integrated IT/OT security, threat intelligence, advanced reporting, and human-centric security awareness.
  • Continuously updated guidance that incorporates industry standards, risk-based approaches, and lessons learned from real-world security programs.

ISOBOK™ serves as a practical reference for establishing, managing, and evolving corporate security organizations, supporting ISOs, governance leaders, and security teams in navigating today’s complex risk landscape.