Security manager/security officer/security director roles and respnsibility

 Often, this is the senior security person within an organization. In some cases, the organization has a CSO (mentioned in the preceding entry of this list), in which case the security officer is a member of senior management. When the senior security role is not a member of senior management, the reporting hierarchy is an essential element of determining the importance and influence security has within the organization. For instance, an organization wherein the security manager reports directly to the CEO places a great deal of importance on security; an organization that has the security manager reporting to an administrative director, who in turn reports to a vice president, who reports to senior management, obviously does not. The security manager is typically responsible for advising senior management on security matters, may assist in drafting security policy, manages day-to-day security operations, represents the organization’s security needs in groups and meetings such as the Configuration Management Board and similar committees, contracts for and selects security products and solutions, and may manage the organization’s response to incidents and disasters.

Note: According to industry best practices, the security manager should not report to the same role/department that is in charge of information technology (IT) because the functions are somewhat adversarial (the security team will be reporting on/reviewing the operations and productivity of the IT team). Having the same department responsible for both functions would constitute a form of conflict of interest. The exception to this is when both the security office and the IT department report to the chief information officer (CIO); this is usually an acceptable form of hierarchy.

Comments

Popular posts from this blog

Security Control Frameworks with full details

Concepts of (CIA) confidentiality, integrity and availability

Organizational Processes and their impact to security