« How to make a nice cup of tea | Main | Storm Worm »

Information Security reporting lines

The question of where Information Security should report into within the organisation has come up in discussion. There is little consistency within my industry contacts. One reports to the CIO, another to a CFO. In my own case I report to a Director of Corporate Governance. Who is the more right? Frankly, I'm not sure that it really matters so long as there is support at the right level for the organisation. There are lots of conflicting views online. Here are some of them:


The right place for information security management is where it belongs; enterprise risk management

If there is an internal audit group, I would say that this function should report wherever this group reports

If you define Information security that it should include data governance and compliance, the methodology I follow make it part of the Business Intelligence organization

Often the most sensible solid line report is to the CIO

I do believe that in many organisations, the infosec function is best positioned reporting directly to the CIO

I think that if Information Security reports into the CIO, Information Security be autonomous from IT Operations


What do you think?

TrackBack

TrackBack URL for this entry:
http://www.computerweekly.com/cgi-bin/mt/mt-tb.cgi/12760

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

About

This page contains a single entry from the blog posted on October 7, 2007 8:05 PM.

The previous post in this blog was How to make a nice cup of tea.

The next post in this blog is Storm Worm.

Many more can be found on the main index page or by looking through the archives.