The Growing Role Of Information Security Managers

May 27, 2008 3:12 PM


         Subscribe in NewsGator Online   Subscribe in Bloglines

The role of information security managers is rapidly changing to focus on business needs instead of technology, according to a recent survey of more than 1,400 Certified Information Security Managers (CISMs) in 83 countries by ISACA, an association of more than 75,000 IT governance professionals worldwide. The Information Security Career Progression Survey Results showed that information security managers experiencing significant career momentum are closely aligned with business goals and priorities.

According to the survey, the career growth pattern among CISMs is clear as they continue to move up into management ranks and acquire more business-focused responsibilities. When asked what their next career step would be, 40.6 percent of respondents said that they intend to step into an executive management role, 40.6 percent intend to step into a chief information security officer (CISO) role and 27.1 percent see themselves in a chief security officer (CSO) role.

The survey also reveals that the top five most common activities performed by information security managers in their current positions are risk management, security program management, data security, policy creation and maintenance and regulatory compliance.

"The role of information security management is quickly evolving to direct the use of technology to solve or prevent business problems instead of being a purely technical specialization,” says Lynn Lawton, international president of ISACA. “It is encouraging to see that CISMs are taking increased responsibility for business functions such as risk management, governance and architecture. These activities help protect the value that information provides to enterprises around the world."

When asked about prior job duties, only 54.8 percent of respondents said that they had responsibility for risk management. In their current position, 75.6 percent said they were responsible for this business-related function. Network security was the third most frequently performed activity in prior positions, but it dropped to eighth in current positions.

"It is clear that Certified Information Security Managers are experiencing career growth and moving up higher into management," says Evelyn Susana Anton, chair of the CISM Certification Board. "This shows that these functions are vital business drivers and are receiving increased attention from boards of directors and executive management."

Designed for experienced information security managers, the CISM designation is a groundbreaking credential earned by more than 9,000 professionals since it was established in 2002. In Certification Magazine’s 2007 Salary Survey, CISM was found to be the second-highest paid certification and was noted as being recognized as an asset among business leaders.

Want to use this article? Click here for options!
© 2009 Penton Media Inc.

Today's New Product

Product 1 Image

Privaris Biometric Verification Software

In support of the Privaris family of personal identity verification tokens for secure physical and IT access, an updated version of its plusID Manager Version 2.0 software extends the capabilities and convenience to administer and enroll biometric tokens. The software offers multi-client support, import and export functionality, more extensive reporting features and a key server for a more convenient method of securing tokens to the issuing organization.

To read more...


Govt Security

Cover

This month in Access Control

Latest Jobs

Popular Stories

Webinar

A Cost-Effective Framework For Total Security Integration

Join AC&SS and MAXxess as they review two different IP-framework applications
Wednesday, July 30, 2008 at 2:00pm ET/11:00am PT

Register Now!

Back to Top