The Information Systems Security Officer's Guide: Establishing and Managing an Information Protection Program, Second Edition

Work is necessary for man. Man invented the alarm clock. Pablo Picasso [1]
We began this section of the book with an overview of the duties and responsibilities of the IWC ISSO, then discussed establishing a CIAPP and the related InfoSec organization. We will continue the trend to narrow the focus: This chapter describes a process to determine what InfoSec functions are needed to successfully establish a CIAPP and related organization, as well as how to incorporate those functions into the InfoSec organization's day-to-day level-of-effort work.
[1]Attributed to Pablo Picasso (1881 1973), Spanish painter and sculptor. Microsoft's Encarta Dictionary.
There are many different ways to configure an InfoSec organization, and there are many ways to configure the InfoSec functions that are part of that organization. Many ISSOs begin establishing an InfoSec organization, or "inheriting" one, without looking at the need for the various functions and from where that need was derived. As stated earlier, all functions should be derived from at least one or more of the following requirements (drivers):
Laws;
Regulations;
Best business practices;
Best InfoSec practices;
Ethics;
Privacy needs; and
IWC policies.
When developing or reorganizing a CIAPP-driven InfoSec organization, one can consider one of three basic structures as it relates to the InfoSec organization that the ISSO will manage and lead. The three basic options are:
Centralized InfoSec under ISSO and InfoSec organization;
Decentralized throughout the corporation; or
A combination of the two.
One of the major factors in deciding what philosophy and...