Who is accountable for protecting the organization?
Leaders of Each Operating Unit
The Organization’s Security Function
Risk assessment, Policy & Supporting Infrastructure
Who reports to a senior-level executive to ensure a strong liaison with leadership, demonstrate commitment and support and highlight the importance of security?
CSD
Security department placement in the organization impacts its ability to:
Key competencies of the CSO
Security Managers
Ratio of direct reports to a single supervisor
Span of Control
A limited number of direct reports
Effective Management
The number depends on:
Generally 1 ; 10 is best, but…
1 to 100 is possible with technology & flattened organization
Management is less important in team environments and flat organizations
And individual reports to only one supervisor
Unity of Command
Three tools of a strategically-managed assets protection program
Assets Protection Program Management
A single office (or person) should be the assets protection focal point
Convergence
Factors that change the understanding of and approach to assets protection:
Five avenues to address risk:
Balancing security and legal considerations:
Five D’s (used to be 3 D’s)
Deter
Deny
Detect
Delay
Destroy
Five forces shaping assets protection:
Globalization in business (increases risks to)
The most effective defense-in-depth program mixes
Defense - in - Depth
Effective Security measures are not oppressive or burdensome
Sarbanes-Oxley Act of 2002