Administrative Issues Flashcards
1
Q
What is a security officer(SO)?
A
A person responsible for information security in an organization.
2
Q
What is the role of a security officer(SO)?
A
- Defines a corporate security policy
- Defines system-specific security policies
- Creates project plan for implementing controls
- Responsible for user awareness and training programs - Appoints auditors
3
Q
Where is the security officer(SO) placed in an organisation’s hierarchy?
A
SO should report to the highest level of control (board of directors, CEO)
SO acts as an intermediary between management and the user base
4
Q
Why is it sometimes hard for the SO to secure support form high-level management?
A
- Ignorance of real nature of risks
- Fixated on bottom line (security costs money, no clear benefits)
- Fear of having to address unknown risks and take responsibility