Chief security officer is responsible for evaluating risk of different business choices and directing the mitigation strategy. CSO is tantamount to a strategic-information risk manager. In many organizations, the CSO reports to the CIO, which is like having the fox guarding the henhouse. The board of directors or CEO should be responsible for finding the right balance between ROI and ROR, says Andreas Antonopoulos, Network World editor-in-chief-at-a-cynio. Antonopoulos: The best solution is to have CSO report to the head of audit or risk management.”]

