Originally posted here by catch
I would add (and this was discussed a bit at the recent ISSA CISO event in San Fran) an incorrect business structure that places corporate security under IT is perhaps the biggest threat to security any corporation can face.

Security should report to a CISO/CSO not CIO/IT director/etc.

cheers,

catch
Hi, can you provide any links for this? I would be very interested to read that.