Is the CISO responsible for purchasing physical security systems/devices?

2.5k viewscircle icon2 Upvotescircle icon7 Comments
Sort by:
Director of Enablement2 years ago

The CISO should be in a position to understand physical security gaps, and identify solutions and tools to plug those holes - but they shouldn’t be on Amazon swiping their cards!

1 Reply
no title2 years ago

I would say follow the business case (justification), and follow the proper purchasing process (purchasing policy).

Director of IT in Education2 years ago

Like Andres said, it depends on the size and structure of the organization. When it involves IT systems, the CISO should be involve in selecting and purchasing to ensure the system’s IT monitoring software meets piece the organization needs, specifically for access controls and other monitoring capabilities for the buildings and data centers the organization is using.

CISO 3 years ago

I don’t think the CISO should be responsible for purchasing. Instead, he should advise his team on the correct security system selection. Before that, the CISO must do a thorough analysis of security systems/devices considering his organization requirement & ISMS polices.

VP Global Cyber & Information Security in Energy and Utilities3 years ago

No, this lies in the domain of the Chief Security Officer, not the Chief Information Security Officer 

CISO in Software3 years ago

I agree with Andres Andreu.  It depends on the company, its size and organization.  Fortune 100 companies may likely have different company and organizational responsibilities that are not all rolled up under a single CISO.

Content you might like

External threats (DDoS attacks, etc.)36%

Internal threats caused by human error (poor password hygiene, phishing, stolen devices, etc.)62%

Something else (comment below)1%

View Results

ZTNA is just a strategy23%

ZTNA can be both a tool & a strategy61%

There are ZTNA tools9%

Not sure5%

View Results