Domain 1: Security and Risk Management

Video transcripts

Every course video in Domain 1, written out so you can search the wording instead of scrubbing through playback.

  • Transcript

    An organization's hierarchy is often determined by the goals of the organization or which industry it operates in. This structure can have a bearing on how security governance is created and implemented or even how security functions are performed. Let's discuss a sampling of various roles pertaining to security encountered in many organizations. This list is in no way inclusive of all types of organizational structures and is not presented as a definitive guide to these roles. It is simply a way to demonstrate the form of some organizations and the bearing of some roles on organizational security, senior management, the upper strata of the organization comprising those officers and executives that have the authority to obligate the organization and to dictate policy. These can include such roles as president, vice president, chief executive officer or CEO, chief operating officer or COO chief information Officer or CIO chief security officer or CSO, chief Financial Officer or CFO. And the like, usually these roles include personnel with some direct legal or financial responsibilities according to statute or regulation.

    Senior management is typically responsible for mandating policy, determining the strategic goals for the organization and making final determinations according to the organizational governance for both security and a non security topics. Security manager and or security officer and or security director. Often this is the senior security person within an organization. In some cases, the organization has a CSO. In which case, the security officer is a member of senior management. When the senior security role is not a member of senior management, the reporting hierarchy is an essential element of determining the importance and influence security has within the organization. For instance, an organization where the security manager reports directly to the CEO places a great deal of importance on security.

    An organization that has the security manager reporting to an administrative director who in turn reports to a vice president who reports to senior management obviously does not. The security manager is typically responsible for advising senior management on security matters and may assist in drafting security policy, manages day to day. Security operations represent the organization's security needs in groups and meetings such as the configuration management board and similar committees, contracts for and select security products and solutions and may manage the organization's response to incidents and disasters. We should also note this according to industry best practices, the security manager should not report to the same role and or department that is in charge of information technology or it because the functions are somewhat adversarial, the security team will be reporting on and or reviewing the operations and productivity of the it team having the same department responsible for both functions would constitute a form of conflict of interest.

    The exception to this is when both the security office and the IT department report to the Chief Information Officer or CIO, this is usually an acceptable form of hierarchy, security personnel, the security practitioners within the organization. These can include administrators, analysts, incident responders and so forth. And this group may also include personnel from disciplines other than it, security such as physical security and personnel, security, security personnel are tasked with performing security processes and activities within the organization. And they usually report to roles as well. These can include secure help desk personnel and network security managers, directors or officers, administrators or technicians. IT personnel who regularly perform work within the environment may have security duties as configuration of systems, applying secure networking reporting, potential incidents and so forth positions in this category include but are not limited to system administrators, often tech support and administrators and or engineers. This group typically reports to the IT director or the CIO, users, employees, contractors and other personnel who operate within the IT environment on a regular basis.

    While this role does not have specific security duties per se, users are required to operate the systems in a secure fashion and they are usually required to sign a formal agreement to comply with security guidance. Users may also be co-opted and trained to report potential security incidents acting as a rudimentary form of intrusion detection. Users typically report to their functional managers.