For Security & Risk Professionals (Length: 14 pages)

July 26, 2007

The Evolving Security Organization

Defining An Appropriate Organizational Structure And Staffing Model For Information Security

by Khalid Kark, Bill Nagel

with Andrew Parker, Jonathan Penn, Alissa Dill


Executive Summary (This is a document excerpt)

In the past few years, the siloed IT security role has rapidly added to its responsibilities and transformed itself into the cross-functional information risk management role. This has left many firms scrambling to structure their security and risk organizations properly and effectively. Corporate executives struggle with organizational structure reporting relationships and staffing decisions for this evolving role. They're starting to realize that there is no right answer that could apply universally to all types of organizations. The roles, responsibilities, staffing, and reporting structure should be based on the company's size, industry, maturity, and corporate organizational structure — but, most importantly, an organization's culture should dictate its security organization archetype. Today, security responsibilities span functional areas and business units. It's very difficult to align, communicate, and involve other business areas; creating a security steering committee could allow you to achieve those objectives.

Buy Risk-Free

Download and print PDF immediately. Price: US $499

Our Money-Back Guarantee: If you are not completely satisfied, return it for a full refund within three weeks of your online purchase.

Already a Forrester Client?
Log in to read this document.

Add to cart

TABLE OF CONTENTS

NOTES & RESOURCES

itemThe Security Organization Grows Up

itemInformation Security Has A New Stature In The Organization

itemOne Size Doesn't Fit All — And Security's No Exception

itemThe Eight Core Security Responsibilities

itemAlignment With IT Ensures Appropriate Implementation Of Security Controls

itemCoordination Outside IT Ensures Appropriate Business Alignment

recommendations

itemEmbed Security In Organizational Processes For Optimum Effectiveness

In developing this research, Forrester drew upon analyst experience, insight, and primary research through interviews with CISOs at end user companies across industry sectors.

Related Research Documents

itemWhat's Top Of Mind For CISOs In 2007

April 17, 2007

itemBridging The Security Divide

January 13, 2006

itemWhere Security Reports Reflects Expanded Role And Responsibilities

September 14, 2005

itemFrom IT Security To Information Risk Management

June 10, 2005

Find Documents In Related Categories

This document falls under the following categories. Click on a link below to find similar documents.

Analyst: Bill Nagel, Khalid Kark
Technology: B2B Sales & Marketing, Corporate Strategy, Human Capital Management, IT Management, IT Organization, Security & Risk, Security Operations, Security Program Governance
Geography: Asia Pacific, Europe, North America

Archived Teleconference:
The Managed Security Services Market Landscape
Original air date: Friday, October 30, 2009
corner border corner
Ratings and Comments
Rating: 9 out of 10
based on 8 ratings across all roles.
corner border corner