Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




basics logo Security Basics mailing list archives

Re: CISO/Security Team roles and functions
From: amatachick () gmail com
Date: 4 Feb 2008 21:02:05 -0000

This is an issue I've run into on every Information Security job. Sometimes Information Security takes care of the 
firewalls and IDSs and sometimes that job goes to the Network Administrators. I've worked in both environments. I have 
to say from personal experience the later is much more common, especially when you get to a management level. I am fine 
with it being either way as long as Information Security can fully, and without the Network Administrator's prior 
knowledge, audit the Firewall and IDS configurations and logs. I don't believe that separation of duties and 
responsibilities applies so much in this scenario as in the bigger picture.

I've run into the most issue with segregation of duties and responsibilities at the departmental level. The key 
question being, who does Information Security report to? I, personally, don't think it should be Information 
Technology. I feel that Information Security should really be its own department or at the least report to compliance 
or legal departments. 

To be succinct, I believe it is the job of Information Security to ensure and/or report incidents, non-compliance to 
policies and procedures, firewalls and IDSs are functioning properly, and conduct audits/assessments.


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]