I can’t help but wonder if the situation might be different if they did not report to IT. We have argued for years that the CISO/CSO should report somewhere other than IT for a number of reasons. Now job security seems to be yet another.
So, give me a few more weeks to learn more. Let me gather additional facts and do some analysis with my peers and see what we think. In the meantime, please write to me–or to bloginfosec– with any stories you have of senior level information security professionals losing their jobs as a result of cost cutting.
Stay tuned!
Popularity: 4%

One Comment
This is cyclical.
Check out one of my first blog posts from 2006 with the spin-down that happened after SoX:
http://www.rationalsurvivability.com/blog/?p=537
Sad.
/Hoff