In Depth
All Over the Map
Where does security fit into the organizational chart? CSOs offer plenty of opinions, but consensus is hard to come by.
By CSO Contributor
Pomeroy was Siemens Canada's CISO until 2001, when he proposed that the company put all security
Other companies describe different structures based on different business needs. As director of corporate security at Crown American Properties, Donald Story runs all aspects of security policy for the company's shopping malls but has little to do with information security. Crown has relatively uncomplicated IT operations
For many companies, today's structure may not work tomorrow; they are still tinkering around with security governance, searching for the most effective combination. One Fortune 1000 medical supply distributor, whose security leader declined to be identified, splits information security and physical security. A vice president of enterprise security, who focuses on information systems security, initially reported to the company's chief privacy officer. Evolving HIPAA requirements (the Health Insurance Portability and Accountability Act) led the company to eventually move the CPO into a compliance group, while the vice president and his infosecurity group were shifted into the CIO's organization. He coordinates with counterparts on the physical side of security where appropriate (but has no official connection on the org chart) and works closely with another important organizational ally for security: the audit function. The vice president's group has worked hand in hand with audit personnel in the process of developing infosecurity policies. "Audit has been a powerful tool for enforcing security procedures," he says. The distribution company generally operates in a decentralized manner, but audit's baseline procedures must be adhered to by all parts of the business. Getting audit buy-in thus gives information security added clout. Sticking Point: InfosecWhat to do with information security is, in fact, the biggest point of controversy.
$firstKeyword
Security Directions: A Virtual Conference
Available On Demand Sept. 30 - Dec. 30
Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.
Protecting PII: How to Work with IT to Manage Risk
Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.



