Executive and board roles in information security
Paul Williams · Network Security · 2007
Corporate information in all its forms is a business asset and needs to be recognised as such. This implies that the ultimate responsibility for security must be accepted by the business and not merely delegated to a chief information security officer (CISO) or equivalent role. The CISO may have delegated responsibility for establishing and managing many of the technical solutions that contribute to information security, but overall governance and assurance of the security's effectiveness must reside with business management. It is with the CEO and the board that the buck stops and, in today's IT enabled and IT dependent world, ignorance and denial are no longer options.