Is the CISO responsible for purchasing physical security systems/devices?

2.5k viewscircle icon2 Upvotescircle icon7 Comments
Sort by:
Director of Enablement2 years ago

The CISO should be in a position to understand physical security gaps, and identify solutions and tools to plug those holes - but they shouldn’t be on Amazon swiping their cards!

1 Reply
no title2 years ago

I would say follow the business case (justification), and follow the proper purchasing process (purchasing policy).

Director of IT in Education2 years ago

Like Andres said, it depends on the size and structure of the organization. When it involves IT systems, the CISO should be involve in selecting and purchasing to ensure the system’s IT monitoring software meets piece the organization needs, specifically for access controls and other monitoring capabilities for the buildings and data centers the organization is using.

CISO 3 years ago

I don’t think the CISO should be responsible for purchasing. Instead, he should advise his team on the correct security system selection. Before that, the CISO must do a thorough analysis of security systems/devices considering his organization requirement & ISMS polices.

VP Global Cyber & Information Security in Energy and Utilities3 years ago

No, this lies in the domain of the Chief Security Officer, not the Chief Information Security Officer 

CISO in Software3 years ago

I agree with Andres Andreu.  It depends on the company, its size and organization.  Fortune 100 companies may likely have different company and organizational responsibilities that are not all rolled up under a single CISO.

Content you might like

Password management/Authentication11%

Endpoint management38%

Identity management30%

Internal threat detection11%

Firewalls3%

Data encryption2%

Other1%

View Results

Yes, always25%

Not always but we test most patches52%

No, only certain patches are tested21%

Other (explain your strategy in comments section)

View Results