A Chief Information Security Officer or CISO, is a job role that focuses on information security strategy within an organization. This security strategy can vary depending on the needs of the enterprise, but often includes responsibility for the following items:
Giga Information Group, a Cambridge, Mass., consulting firm, estimates that fewer than 10% of large companies had adopted the role of a chiefsecurityofficer prior to Sept. 11.
Chief areas of conflict center around which side of the business the chiefsecurityofficer comes fromthe physical security side of the business, or the information technology side of the businessand to whom he or she reports.
In the absence of a chiefsecurityofficer, both the physical and electronic security executives in a company should report to one senior executive.
Security professionals offer knowledge and expertise that should be influencing student, faculty and staff communications and training regarding illegal and unethical behavior.
Although information technology is a major component of this process, the overall sensitive informationsecurity mechanism should not be left completely to IT.
Secure both nonpublic and public personal information and any lists that may be derived from this information - GLB includes provisions for the release of both private and public information.