The Information Systems Security Officer's Guide: Establishing and Managing an Information Protection Program, Second Edition

There are many debates as to where the information and information systems security (InfoSec) and the information systems security officer (ISSO) position fit in a company or government entity. Some believe it belongs in the information technology (IT) department, others say it belongs in the security department. Others believe it should report to the CEO, CIO, or some level of executive management other than the two mentioned.
The IT people may want control of the InfoSec function so that they can ensure that it does not hamper their IT functions. A corporate security manager may want the function to be sure these valuable assets, like other assets whose protection is the responsibility of the security department, are properly protected.
Four individuals, with different backgrounds and InfoSec responsibilities over the many years they have been in the business, share their views on InfoSec and the ISSO function. They are:
William "Bill" C. Boni: Mr. Boni is the Vice President and Chief Information Security Officer, Motorola Information Protection Services (MIPS), Motorola Corporation.
Edward Halibozek: Mr. Halibozek is the Corporate Director of Security, and IS Sector & Western Region Manager Security, for a multi-billion-dollar, global corporation headquartered in Los Angeles, California, USA.
Andy Jones: Mr. Jones was the business manager for the Secure e-Business department of QinetiQ, the privatized portion of Defense Evaluation and Research Agency (DERA), Malvern, United Kingdom. He is now a senior lecturer at the University of Glamorgan, Wales, United Kingdom.
Steve Lutz: Mr. Lutz is the...