Governing Security When the CISO Advises but Doesn’t Command – by Kamran Israr Mirza (Kim)

Governing Security When the CISO Advises but Doesn’t Command – by Kamran Israr Mirza (Kim)

A significant share of organizations still place the Security Operations Center (SOC) organizationally under the Chief Technology Officer, while the Chief Information Security Officer and a small security function operate in a largely advisory capacity: setting policy and standards, but without direct authority over SOC staffing, tooling roadmaps, or incident-response resourcing. This white paper examines what that structure does to governance, and what it means for organizations simultaneously pursuing PCI DSS, ISO/IEC 27001, and ISO/IEC 42001 compliance.

It answers a question many boards leave unresolved: who owns the risk register and the Risk and Control Self-Assessment (RCSA) process when operational security sits inside the technology function. It also ranks the most common headaches this model creates for the CISO, and closes with a SWOT analysis and a set of recommendations.

The core argument: it is the CISO, not the CTO or the SOC, who ultimately answers for every certification the organization holds, and that accountability only works if matched with real independence. The paper’s leading recommendations are to elevate the CISO’s reporting line to the CEO or the Board rather than the COO, CIO, or CTO, and to give the security function its own CAPEX and OPEX budget, alongside interim governance measures for organizations that cannot make those changes immediately.

Kim is an experienced CISO, an ISACA Platinum Member, and a member of the Pakistan Engineering Council (MPEC). Find him on LinkedIn at linkedin.com/in/kimabdalian