<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Information Security: Orphan of the Org Chart?</title>
	<atom:link href="http://www.bloginfosec.com/2008/03/14/information-security-orphan-of-the-org-chart/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.bloginfosec.com/2008/03/14/information-security-orphan-of-the-org-chart/</link>
	<description>An Information Security Magazine in a Blog Format</description>
	<lastBuildDate>Mon, 30 Jan 2012 11:01:25 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Doug Copley</title>
		<link>http://www.bloginfosec.com/2008/03/14/information-security-orphan-of-the-org-chart/comment-page-1/#comment-3660</link>
		<dc:creator>Doug Copley</dc:creator>
		<pubDate>Mon, 21 Apr 2008 05:30:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.bloginfosec.com/2008/03/14/information-security-orphan-of-the-org-chart/#comment-3660</guid>
		<description>I work at a fairly large financial services company and we&#039;re struggling with this question right now.  We&#039;re considering combining the policy &amp; awareness functions of 3 groups into one:  information security, records management and privacy.  Together they may equate to something called the Office of Information Assurance.  Where they should report is the biggest question.  The most logical place in my mind so far is either the Enterprise Risk Office (most logical), or Legal (records mgmt and privacy are already there).  

I&#039;d be grateful to any other financial companies who&#039;d like to chime in with their current organizational placement.</description>
		<content:encoded><![CDATA[<p>I work at a fairly large financial services company and we&#8217;re struggling with this question right now.  We&#8217;re considering combining the policy &amp; awareness functions of 3 groups into one:  information security, records management and privacy.  Together they may equate to something called the Office of Information Assurance.  Where they should report is the biggest question.  The most logical place in my mind so far is either the Enterprise Risk Office (most logical), or Legal (records mgmt and privacy are already there).  </p>
<p>I&#8217;d be grateful to any other financial companies who&#8217;d like to chime in with their current organizational placement.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

