Trend Report

The Evolving Security Organization

Defining An Appropriate Organizational Structure And Staffing Model For Information Security

Khalid Kark
Bill Nagel
 and  three contributors
Jul 26, 2007

Summary

In the past few years, the siloed IT security role has rapidly added to its responsibilities and transformed itself into the cross-functional information risk management role. This has left many firms scrambling to structure their security and risk organizations properly and effectively. Corporate executives struggle with organizational structure reporting relationships and staffing decisions for this evolving role. They're starting to realize that there is no right answer that could apply universally to all types of organizations. The roles, responsibilities, staffing, and reporting structure should be based on the company's size, industry, maturity, and corporate organizational structure — but, most importantly, an organization's culture should dictate its security organization archetype. Today, security responsibilities span functional areas and business units. It's very difficult to align, communicate, and involve other business areas; creating a security steering committee could allow you to achieve those objectives.

Log in to continue reading
Client log in
Welcome back. Log in to your account to continue reading this research.
Become a client
Become a client today for these benefits:
  • Stay ahead of changing market and customer dynamics with the latest insights.
  • Partner with expert analysts to make progress on your top initiatives.
  • Get answers from trusted research using Izola, Forrester's genAI tool.
Purchase this report
This report is available for individual purchase ($1495).