Thank you for Subscribing to CIO Applications Weekly Brief
A featured contribution from Leadership Perspectives, a curated forum for enterprise technology leaders, nominated by our subscribers and vetted by the CIOApplications Editorial Board.

Inc.
Dr. Garrett Smiley, CISO, SERCO
InfoSec's Purpose, Role, & Relationships


According to SearchSecurity (TechTarget), Information Security (InfoSec) is a set of strategies for managing the processes, tools, and policies necessary to detect, document, and respond to threats against digital and non-digital information. Often, the terms for InfoSec and Cybersecurity are used interchangeably, but it should be noted that InfoSec is a term most often used in defensive terms, whereas cybersecurity is most often used in offensive terms. The US government prefers the term Information Assurance (IA), which is focused on protecting information systems and utilizes a risk management framework.
InfoSec’s Purpose
The purpose of InfoSec can be summed up in two bullets:
• Early: Assist with establishing secure organizational approaches in and with all things (people, processes, technology, environment, etc.), considering the most likely risks and issues and recommending and guiding the implementation of controls to mitigate those risks and issues
• Later: Monitor and respond to potential or actual exploits of vulnerabilities across our organization (e.g., Contracts, IT, Legal, Procurement, etc.) in a continuous fashion
The organizational role of InfoSec can be summed up in three bullets:
1. Business Enablement: To enable the business to achieve its mission, vision, goals, and objectives in the most secure manner possible based on risk appetite
2. Risk Identification: To drive awareness of risks and issues posed to the organization in a format that is tailored for the respective audience, maximizing the understanding of the associated material impact of those risks and issues
3. Risk Consultancy: To provide informed advice, guidance, and potential solutions concerning risks and issues in the environment, supporting solution efforts when adopted and implemented
InfoSec’s Relationship to Others
InfoSec’s relationship to other entities within the organization can be summarized as follows:
• The Board of Directors: inform them on risks that present liability to the organization
• The Executive Management Team (EMT): demonstrate how risk is managed within the organization with the available spend and staff
• Departments: identify where risk can be reduced respective to their function
• Employees: educate them on avoiding risky behavior
• Third Parties: determine the risk they pose to the organization
Even though this overview may seem to be at a rather high level, leaning almost too much towards the abstract, it should be noted that the purpose, role, and relationship with InfoSec has undergone a dramatic shift. It is the shift from the historical understanding of InfoSec as a control function being nothing more than a beat cop, issuing orders to stop doing things to a risk management function, where InfoSec enables the business to do things in a properly risk adverse way. InfoSec can partner with risk management and internal audit to help their organization better identify the risk in the organization, regardless of what type of risk that may be. It should not matter how a risk is categorized (i.e., cost, schedule, programmatic, technical, etc.), but rather the potential impact and likelihood of that risk against critical assets for the organization. Just as risks in an organization should not be siloed to a particular area or department, nor should risk management controls be segregated within the organization.

