From the course: ISC2 Certified Information Systems Security Professional (CISSP) (2024) Cert Prep

Unlock this course with a free trial

Join today to access over 23,200 courses taught by industry experts.

Security roles and responsibilities

Security roles and responsibilities

- [Instructor] Security roles and responsibilities may differ between organizations, but there are several common themes that exist across almost all businesses. The senior information security leader in an organization is commonly known as the Chief Information Security Officer, or CISO. Now, this title is also sometimes pronounced CISO. In some organizations, the CISO may have a different title, such as Director of Information Security, or Chief Security Officer. Another difference between organizations lies in where the CISO reports. In some cases, the CISO reports to the Chief Information Officer, an organization's most senior IT leader. In other cases, the CISO reports to a risk management or audit function, providing a degree of separation between the individual responsible for IT and the individual responsible for ensuring that IT has effective security controls. The CISO normally leads a team of information security professionals. The size of that team will vary depending upon…

Contents