mixma242 wrote on Oct 4, 2017, 12:45:
At the moment I am studying for the CISSP (Certified Information Systems Security Professional). The CISSP is a high level security cert, and here is a direct quote:
"Security governance is not and should not be treated as an IT issue only. Instead, security affects every aspect of an organization. It is no longer just something the IT staff can handle on their own. Security is a business operations issue. Security is an organizational process, not just something the IT geeks do behind the scenes."
It goes on to emphasize that senior management must be engaged in business security and that they have the ultimate responsibility, not the IT department.
Agree 100%. Sadly, this still seems to utterly baffle 99.99% of all corporate users out there.