The Information Security Organization
Patrick D. Howard · Auerbach Publications eBooks · 2011
FISMA requires the establishment of an organization-wide information security function. To establish an enterprisewide security program such as one required by FISMA, centralization makes it far easier to implement such a program. Centralized program management facilitates the program’s penetration enterprisewide, into all business units, across all geographical locations, and applicable to all users of the organization’s information technology resources. Centralization permits dissemination and enforcement of a single information security policy that applies to the entire enterprise, and is more advantageous than the management of multiple security policies, which will almost always prove dicult to integrate.