nerdexam
(ISC)2

SSCP · Question #278

In an organization, an Information Technology security function should:

The correct answer is C. Be lead by a Chief Security Officer and report directly to the CEO.. In order to offer more independence and get more attention from management, an IT security function should be independent from IT and report directly to the CEO. Having it report to a specialized business unit (e.g. legal) is not recommended as it promotes a low technology view o

Submitted by hans_de· Apr 18, 2026Security Concepts and Practices

Question

In an organization, an Information Technology security function should:

Options

  • ABe a function within the information systems function of an organization.
  • BReport directly to a specialized business unit such as legal, corporate security or insurance.
  • CBe lead by a Chief Security Officer and report directly to the CEO.
  • DBe independent but report to the Information Systems function.

How the community answered

(30 responses)
  • B
    7% (2)
  • C
    90% (27)
  • D
    3% (1)

Explanation

In order to offer more independence and get more attention from management, an IT security function should be independent from IT and report directly to the CEO. Having it report to a specialized business unit (e.g. legal) is not recommended as it promotes a low technology view of the function and leads people to believe that it is someone else's problem.

Topics

#Organizational Structure#Security Governance#Reporting Lines#Chief Security Officer

Community Discussion

No community discussion yet for this question.

Full SSCP Practice