ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Can cyber security and IT have the same reports?

    IT Careers
    3
    7
    780
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • IRJI
      IRJ
      last edited by

      Essentially in cyber security you could be reporting on your bosses if you're under your IT. In CISSP and some of the other courses I have taken have said IT security should be under a different reports. How does your company handle that?

      1 Reply Last reply Reply Quote 1
      • scottalanmillerS
        scottalanmiller
        last edited by

        In my experience there is a mix. IT is cyber security to the users, and security is security to IT. Two different C levels.

        Does that make sense?

        IRJI 1 Reply Last reply Reply Quote 0
        • IRJI
          IRJ @scottalanmiller
          last edited by IRJ

          @scottalanmiller said in Can cyber security and IT have the same reports?:

          In my experience there is a mix. IT is cyber security to the users, and security is security to IT. Two different C levels.

          Does that make sense?

          I think you misunderstood.

          Should the departments be separated? Should the CISO be a part of IT or compliance?

          DashrenderD scottalanmillerS 2 Replies Last reply Reply Quote 0
          • DashrenderD
            Dashrender @IRJ
            last edited by Dashrender

            @IRJ said in Can cyber security and IT have the same reports?:

            @scottalanmiller said in Can cyber security and IT have the same reports?:

            In my experience there is a mix. IT is cyber security to the users, and security is security to IT. Two different C levels.

            Does that make sense?

            I think you misunderstood.

            Should the departments be separated? Should the CISO be a part of IT or compliance?

            I'm pretty sure he said they should be part of compliance. That's the two different C levels. One C level is IT (CIO), the other C level is compliance/etc (possibly the CFO).

            IRJI scottalanmillerS 2 Replies Last reply Reply Quote 1
            • IRJI
              IRJ @Dashrender
              last edited by

              @Dashrender said in Can cyber security and IT have the same reports?:

              @IRJ said in Can cyber security and IT have the same reports?:

              @scottalanmiller said in Can cyber security and IT have the same reports?:

              In my experience there is a mix. IT is cyber security to the users, and security is security to IT. Two different C levels.

              Does that make sense?

              I think you misunderstood.

              Should the departments be separated? Should the CISO be a part of IT or compliance?

              I'm pretty sure he said they should be part of compliance. That's the two different C levels. One C level is IT (CIO), the other C level is compliance/etc (possibly the CFO).

              That is what is considered best practice, but it's not always what I've seen.

              1 Reply Last reply Reply Quote 0
              • scottalanmillerS
                scottalanmiller @Dashrender
                last edited by

                @Dashrender said in Can cyber security and IT have the same reports?:

                @IRJ said in Can cyber security and IT have the same reports?:

                @scottalanmiller said in Can cyber security and IT have the same reports?:

                In my experience there is a mix. IT is cyber security to the users, and security is security to IT. Two different C levels.

                Does that make sense?

                I think you misunderstood.

                Should the departments be separated? Should the CISO be a part of IT or compliance?

                I'm pretty sure he said they should be part of compliance. That's the two different C levels. One C level is IT (CIO), the other C level is compliance/etc (possibly the CFO).

                Compliance should never be under a totally arbitrary team like finance. Especially not finance. That's just as bad as being under IT. If finance is stealing money, and they are the most likely ones to do so, they'd control their own audits!

                1 Reply Last reply Reply Quote 0
                • scottalanmillerS
                  scottalanmiller @IRJ
                  last edited by

                  @IRJ said in Can cyber security and IT have the same reports?:

                  @scottalanmiller said in Can cyber security and IT have the same reports?:

                  In my experience there is a mix. IT is cyber security to the users, and security is security to IT. Two different C levels.

                  Does that make sense?

                  I think you misunderstood.

                  Should the departments be separated? Should the CISO be a part of IT or compliance?

                  By definition, I feel, a CISO cannot be under another CxO except for the CEO.

                  1 Reply Last reply Reply Quote 1
                  • 1 / 1
                  • First post
                    Last post