The Information Systems Security Officer's Guide: Establishing and Managing an Information Protection Program, Second Edition

Responsible, who wants to be responsible? Whenever something bad happens, it's always, who's responsible for this? Jerry Seinfeld [1]
The objective of this chapter, "The ISSO's Position, Duties, and Responsibilities," is to define the role that the ISSO will play in a corporation or government agency. In this case, it is the role of the ISSO for IWC. The duties and responsibilities of an ISSO vary depending on the place of employment. However, in this case, we are assuming the ISSO has the perfect position because it is one all ISSOs should strive to attain in order to "do it right the first time."
[1] Reader's Digest, October 2002, p. 73.
The position of the ISSO has evolved over the years. We began with only physical security, as after all, the ENIAC and others did not connect to the world. A guard, a paper authorized personnel access list, an alarm, and such were all that were needed in those early days. But as the computer evolved over time, so did the profession of the ISSO.
The security profession at that time was primarily made up of retired or former law enforcement or military personnel, who had no interest in computer security. They knew physical security, investigations, and personnel security. This new thing called a computer was best left to the computer scientists and engineers.
As systems evolved, so did the departments responsible for their support. Departments that were once engineering departments perhaps became information resource...