Management of Information Security, Fourth Edition 5-4
Placing Information Security within an Organization
1. Describe where information security departments are typically placed in large
organizations, and note that these departments are headed by the CISO, who reports to
the CIO.
2. Emphasize that organizations should strive to find a place for the information security
Responsibilities Made Easy book.
Components of the Security Program
1. Explain that the strategic plan and the organization’s vision and mission statements
determine how an information security program will operate.
2. Describe Charles Cresson Wood’s recommendations on the formulation of mission
statements
3. Discuss the two documents from NIST that provide guidance for the development of an
InfoSec program:
b. SP 800-12 (An Introduction to Computer Security: The NIST Handbook)
4. List some of the different topics covered by the NIST Handbook:
a. Elements of computer security
g. Contingency planning
5. Discuss some of the essential InfoSec program elements that presented in the SP 800–
14 and SP 800-12 documents, such as policy, risk management, awareness and training,
and audit trails.
Information Security Roles and Titles
1. Explain that information security positions can be classified into three types: those that
define, those that build, and those that administer.
2. Provide a list of the different categories that most security related responsibilities will
fall under:
a. CISCO or CSO