Advertisement

10.12.2008 at 11:17AM PDT, ID: 23807940 | Points: 250
[x]
Attachment Details

Examples of Information Security Organization Model

Asked by zoomeroo in Miscellaneous Security, Networking Security Vulnerabilities, Operating Systems Network Security

Our current information security organization needs revamping. We have a bunch of different products we use, processes defined, but generally disorganized. We are not doing anything in terms of security strategy. We now have budget to expand resources and want to setup ourselves "properly" in terms of an organizational model. I have looked into SABSA, NIST, as well as ISO but none really connect the theoretical with the practical. Does anyone have recommendations starting with a VP/Director of security on down?This would be for a general corporation (e.g. financial services). We need to cover things like operations (keeping the monitoring processes running), forensics/investigations, and keeping all the products we use updated as well as minor development to automate things here and there.

Can anyone point me in a good direction? In addition, with that org chart, it would be nice to be able to figure out each branch would "hand off" to one another -- how they all play together. Start Free Trial
[+][-]10.13.2008 at 09:26AM PDT, ID: 22703734

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]10.16.2008 at 02:37AM PDT, ID: 22729136

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628