Security Basics mailing list archives

Re: Sizing the Information Security Department


From: "exzactly" <exzactly () hotmail com>
Date: Fri, 5 Sep 2008 08:20:21 -0700

1/3 of the IT staff should be dedicated towards security. That doesn't mean that you ness. need to hire that many but 1/3 of the man hours int he department shoudl be dedicated to it.


----- Original Message ----- From: <k7.fantr () gmail com>
To: <security-basics () securityfocus com>
Sent: Thursday, September 04, 2008 3:22 PM
Subject: Sizing the Information Security Department


Hello all.

I am preparing a business case for increasing the size of the Information Security department at the company where I work. This is a smaller company with about 700 employees. Right now, I am the security department. :) - I am asking to hire 3 security professionals to augment my load and to allow me to focus on more of the strategic needs and higher level analysis.

My question is this: Do any of you know of any published recommendations regarding the size of a security department based on company size? Any guidance in this regard is appreciated.

Thanks in advance!





Current thread: