Responsibilities for IS
Information security is a process and everyone needs to be involved at all times
CISO
Central resource and primary responsibility for the assessment, management and implementation of information security within the Organization
CISO responsibilities
CIO
executive level position that oversees the organization’s computing technology and strives to create efficiency in the processing and access of the organization’s information
Information Security Steering Committee
Data Protection Officer
is responsible for ensuring an organizations adherence to laws and actions to protect individuals personal data
Responsibiliets
conflict of interest with cio (data protection hinders information processing)
additional roles
it security manager
Project security managers:
Audit and compliance group
But: IT manager not IT security Manager not Information Security manager (CISO)
Firm Networks
Third parties process information, offer support, services etc.:
an organization must have policies for third party arrangements:
Third party may work with further subcontractors as well:
There is little sense in comprehensive and expensive protection of parts of network if other part of a network have low levels of security