QuestionQ429

Security Concepts and Practices

Within an organization, an Information Technology security function should:

  • A Be a function within the information systems function of an organization.
  • B Report directly to a specialized business unit such as legal, corporate security or insurance.
  • C Be lead by a Chief Security Officer and report directly to the CEO.
  • D Be independent but report to the Information Systems function.
Explanation

An IT security function should have enterprise-wide authority and organizational independence so it can set policy, manage risk, and escalate security issues without being subordinated to the IT operations it oversees. Leadership by a Chief Security Officer reporting directly to the CEO provides that independence and executive accountability.

Community Discussion

No comments yet. Be the first to start the discussion!