Who makes security purchasing decisions

Who makes security purchasing decisions

Could you tell me who makes security purchasing decisions in most enterprises?


    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

In most enterprises, there is no single coordinated place that security purchasing decisions are made. That is part of the problem many businesses are having.

A typical situation is that one groups runs the company Web servers, and they provide whatever security products those servers use. Another group is responsible for desktop services, e-mail, etc., and that group makes security purchase decisions for those products. If the company has a CIO, the CIO office will often mandate certain security products to be used, usually without coordinating with the two groups above. Individual offices, or even users, might procure their own security products, as well.

It is rare to find a company that has a single decision point. The most effective companies will have their IT support reporting to the company CIO, and they will be responsible for all IT within the company. This includes desktops, servers, firewalls, networks and anything else needed. In this way, they can develop an appropriate security architecture for the company and procure products to implement that architecture. So, the head of the IT support or the CIO would be the decision point for security purchases.


For more information on this topic, visit these other SearchSecurity.com resources:
Best Web Links: Budgeting for Security
Featured Topic: Security Budgets
Executive Security Briefing: Security spending a necessary evil


This was first published in February 2002