Posted on 2002-03-10
Last Modified: 2010-04-11

 Hi expsrts,

  I need your opinion in this question :-

  Do you think that IT Security Department can be   considered as either a part of the Corporate IT support department or as part of the Corporate Security department? and why ? please justify your chosen line ?
Question by:saeeddxb
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
LVL 11

Expert Comment

ID: 6855624
It would depend on the business model.  The particular expertise required for IT security is most offt4en found in or related to IT, but security is a defense in depth concept that also requires physical security.  As a general rule I would say that it should be under IT with stronger connections to corporate security.

Author Comment

ID: 6856041

 what do you mean with business model ? for example im
 an IT manager of a company of 2000 employee and for a budget reason you have been asked to consider the above question ?
LVL 11

Expert Comment

ID: 6856969
For most companies up to a certain size, they may not have a well defined coporate security department, but almost all will have an IT department.  Therefore IT security fits well into IT in that business model.  Larger comapnies are more granular in their model and may have the resources to separate out this function.
Get 15 Days FREE Full-Featured Trial

Benefit from a mission critical IT monitoring with Monitis Premium or get it FREE for your entry level monitoring needs.
-Over 200,000 users
-More than 300,000 websites monitored
-Used in 197 countries
-Recommended by 98% of users

LVL 24

Accepted Solution

SunBow earned 100 total points
ID: 6861718
> IT Security Department can be considered as either a part of the Corporate IT support department or as part of the Corporate Security department?

No. No choice. It is first one, period.

> and why ?

This "Corporate Security department" is title for building security, guard at door, having employees wear badges, rules like that, even parking regultions and which doors can be used for coming and going, and what you can physically take in or out of a building or room. This is not what I call IT, also there'd be some overlap for situations involving employee badges that can also permit electronic access to rooms or computers.

> IT Security IT support

If no better reason here, These both have acronymn "IT"

Similar answer if acronymn is "IS"

These involve corporate information and how it is maintained electronically. The building people can use keys, sheets of paper and pen, do not need electronics. IS and IT can live without keys, or pens, but need the electronics for their tasks concerning corporate information.
LVL 24

Expert Comment

ID: 6861727
> For most companies up to a certain size,

yeah, in a big building, small company may have no choice on building security. But have the choice for their IT staff functions.

This could be farmed out, hiring contractor or consultants to run, but it remains same kind of function, using the electronics.
LVL 24

Expert Comment

ID: 6861752
> under IT with stronger connections to corporate security

I think this has changed, if for no other reason than worms, outlook, and firewalling. It used to be that any corporate security job was just making rules and delivering sheets of paper saying "obey rules".

But now, you really have to have a much better grasp on IT in order to understand how to make up rules, and which ones should be more prioritised.

For example, some old 'rules' would go simply "no personal email", "do not surf internet", very impersonal and impractical.

Now, they may need to learn forensics, or how to use computer-enabled tools to make discoveries.

So a more interesting question could be, how closely they are getting related to Network Administration these days.
LVL 11

Expert Comment

ID: 6861764
A number of Fortune 500 companies rely on the (ISC)2 model for Information Security.  This model specifies that physical access is a strong requirement for IS.  It also specifies that process and human factors contribute IS breach.  To that end, they have consolidated their security.

Is the technology different , yes.  Is the point different, no.  The point is to preserve intellectual property and commany assets.  
LVL 24

Expert Comment

ID: 6865907
I'm not sure if this helps your situation, but I concur with geoffryn concerning inattentiveness to internal physical security. While a virus or worm gets headliner, substantial and perhaps more abuse can arise from disgruntled employees, or simply, from being too lax. Physical access (to buildings, to rooms, to keyboards) is among the more difficult to defend, and must be coordinated in effort with all others that are involved in aspects of security.

How to do that, remains open question, at least in USA I see they are making more and more agencies for something 'security'. I am supposing they are refining the how-to.

Expert Comment

ID: 6866434
IT is IS is IT is.
LVL 24

Expert Comment

ID: 6869976
Thanx, &
Good Fortune!

Featured Post

Optimize your web performance

What's in the eBook?
- Full list of reasons for poor performance
- Ultimate measures to speed things up
- Primary web monitoring types
- KPIs you should be monitoring in order to increase your ROI

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A 2007 NCSA Cyber Security survey revealed that a mere 4% of the population has a full understanding of firewalls. As business owner, you should be part of that 4% that has a full understanding.
Recovering from what the press called "the largest-ever cyber-attack", IT departments worldwide are discussing ways to defend against this in the future. In this process, many people are looking for immediate actions while, instead, they need to tho…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…
Suggested Courses
Course of the Month9 days, 5 hours left to enroll

615 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question