In the 1980s and 1990s, organizations recognized that information was strategic to their operations and that they needed to put a Chief Information Officer in charge of IT. But in this era of cyberattacks, it’s hard if not impossible to isolate IT from security. Not all CIOs are enamored of the idea that there ought to be an independent CSO function in the reporting structure. CSOs have a complementary not subservient role and should take charge of security controls, auditing, and testing.”]
Source: https://www.csoonline.com/article/3099212/dividing-the-security-pie-who-should-get-what.html