Should security team be part of Technology
Every company that I ever worked at security has always been part of technology teams and has always evolved out of technology teams as have I.
Nothing wrong with it if that is where it doesn’t permanently reside and here is why.
Dr. Eric Cole says a CISO reporting to a CIO presents a conflict of interest and I agree.
CIO is responsible and is interested in providing technology that enables and empowers the business.
CISO wants to ensure the business assets are secure, and may want to patch internet facing systems if there are critical vulnarabilities and this causes downtime conficting with the CIOs needs.
I do agree with Dr. Cole that this is a decision for the executive leadership to make and a CISO reporting to CIO means this may never get presented to the CEO to either accept the risk or mitigate it.