---
title: "SE Guest Blog: Information Security Officer - It's not just a cool title"
description: Tom Loring, MBA, CISA at Macpage explains the important roles and responsibilities that come with the job of the Information Security Officer.
image: https://blog.systemsengineering.com/hubfs/blog-files/TLoring.jpg
---

[![header-logo](https://blog.systemsengineering.com/hs-fs/hubfs/header-logo.png?width=138&name=header-logo.png)](https://www.systemsengineering.com)

888.624.6737

<https://www.linkedin.com/company/systemsengineering-><https://www.facebook.com/systemsengineeringinc>

![Spyglass](https://www.systemsengineering.com/wp-content/uploads/search-google-e1751908066340.png)

- [Careers](https://www.systemsengineering.com/about/careers/)
- [Blog](https://blog.systemsengineering.com/blog)
- [Events](https://www.systemsengineering.com/news-resources/events/)
- [Case Studies](https://www.systemsengineering.com/case-studies/)
- [Client Center](https://www.systemsengineering.com/client-center/)
- [CONTACT](https://www.systemsengineering.com/about/contact/)

- IT Services 
    - [Managed IT](https://www.systemsengineering.com/managed-it/) 
          - [IT Essentials](https://www.systemsengineering.com/managed-it/it-essentials/)
          - [Microsoft Services](https://www.systemsengineering.com/managed-it/microsoft-services/)
          - [Modern Workplace](https://www.systemsengineering.com/managed-it/modern-desktop/)
          - [Help Desk](https://www.systemsengineering.com/managed-it/help-desk/)
          - [Network Assessment](https://www.systemsengineering.com/managed-it/network-assessment/)
    - [IT Consulting Services](https://www.systemsengineering.com/it-consulting-services/) 
          - [Compliance](https://www.systemsengineering.com/compliance)
          - [IT Policies-as-a-Service](https://www.systemsengineering.com/it-consulting-services/it-policies-as-a-service/)
          - [Virtual CIO](https://www.systemsengineering.com/it-consulting-services/virtual-cio/)
          - [Engineering Services](https://www.systemsengineering.com/it-consulting-services/engineering-services/)
          - [Project Management](https://www.systemsengineering.com/it-consulting-services/project-management/)
          - [Business Continuity](https://www.systemsengineering.com/it-consulting-services/business-continuity/)
          - [Assessments & Gap Analyses](https://www.systemsengineering.com/it-consulting-services/get-it-assessed/)
    - [Software Services](https://www.systemsengineering.com/software-services/) 
          - [Application Development](https://www.systemsengineering.com/software-services/application-development/)
          - [SharePoint](https://www.systemsengineering.com/software-services/sharepoint/)
          - [Database Services](https://www.systemsengineering.com/software-services/database-services/)
- [IT Security](https://www.systemsengineering.com/security/) 
    - [Adaptive Cybersecurity Framework (aCSF)](https://www.systemsengineering.com/se-adaptive-cybersecurity-framework-acsf/)
    - [Cloud Security](https://www.systemsengineering.com/security/cloud-security/) 
          - [Cloud Security Resources](https://www.systemsengineering.com/security/cloud-security/cloud-security-resources/)
    - [Security Awareness Training](https://www.systemsengineering.com/security/security-awareness-training/)
    - [Cybersecurity Risk Assessment](https://www.systemsengineering.com/security/cybersecurity-risk-assessment/)
- [Compliance](https://www.systemsengineering.com/compliance/) 
    - [Cybersecurity Maturity Model Certification (CMMC)](https://www.systemsengineering.com/compliance/cmmc-compliance/) 
          - [CMMC Compliance Service](https://www.systemsengineering.com/compliance/cmmc-compliance/cmmc-compliance-service/)
          - [CMMC Resources](https://www.systemsengineering.com/compliance/cmmc-compliance/cmmc-resources/)
    - [National Credit Union Administration (NCUA)](https://www.systemsengineering.com/compliance/ncua/)
- [Cloud Services](https://www.systemsengineering.com/cloud-services/) 
    - [Cloud Management](https://www.systemsengineering.com/cloud-services/cloud-management/)
    - [Cloud Security](https://www.systemsengineering.com/security/cloud-security/)
    - [Office 365 Migration & Support](https://www.systemsengineering.com/cloud-services/office-365-migration-support/) 
          - [Office 365 Backup](https://www.systemsengineering.com/cloud-services/office-365-migration-support/office-365-backup/)
    - [Cloud Assessment](https://www.systemsengineering.com/cloud-services/cloud-assessment/)
- [Industries](https://www.systemsengineering.com/industries/) 
    - [Construction](https://www.systemsengineering.com/industries/construction/)
    - [Education](https://www.systemsengineering.com/industries/education/)
    - [Financial Services](https://www.systemsengineering.com/industries/financial-services/) 
          - [Accountants & Wealth Managers](https://www.systemsengineering.com/industries/financial-services/accountants-wealth-managers/)
          - [Banks](https://www.systemsengineering.com/industries/financial-services/banks/)
          - [Credit Unions](https://www.systemsengineering.com/industries/financial-services/credit-unions/)
    - [Government](https://www.systemsengineering.com/industries/government/)
    - [Healthcare](https://www.systemsengineering.com/industries/healthcare/)
    - [Law Firms](https://www.systemsengineering.com/industries/legal/)
    - [Manufacturers](https://www.systemsengineering.com/industries/manufacturer/)
    - [Nonprofit](https://www.systemsengineering.com/industries/nonprofits/)
- [About](https://www.systemsengineering.com/about/) 
    - [Leadership](https://www.systemsengineering.com/about/leadership/)
    - [Our Difference](https://www.systemsengineering.com/about/our-difference/)
    - [Our Partners](https://www.systemsengineering.com/about/our-partners/)
    - [Culture](https://www.systemsengineering.com/culture/)
    - [Contact](https://www.systemsengineering.com/about/contact/)

- Managed IT 
    - [Overview](https://www.systemsengineering.com/managed-it/)
    - [IT Essentials](https://www.systemsengineering.com/managed-it/it-essentials/)
    - [Microsoft Services](https://www.systemsengineering.com/managed-it/microsoft-services/)
    - [Modern Workplace](https://www.systemsengineering.com/managed-it/modern-workplace/)
    - [Help Desk](https://www.systemsengineering.com/managed-it/help-desk/)
    - [Network Assesment](https://www.systemsengineering.com/managed-it/network-assessment/)
- IT Consulting Services 
    - [Overview](https://www.systemsengineering.com/it-consulting-services/)
    - [Virtual CIO](https://www.systemsengineering.com/it-consulting-services/virtual-cio/)
    - [CMMC Compliance](https://www.systemsengineering.com/compliance/cmmc-compliance/)
    - [IT Policies-as-a-Service](https://www.systemsengineering.com/it-consulting-services/it-policies-as-a-service/)
    - [Engineering Services](https://www.systemsengineering.com/it-consulting-services/engineering-services/)
    - [Project Management](https://www.systemsengineering.com/it-consulting-services/project-management/)
    - [Business Continuity](https://www.systemsengineering.com/it-consulting-services/business-continuity/)
    - [Assessments & Gap Analyses](https://www.systemsengineering.com/it-consulting-services/get-it-assessed/)
- Software Services 
    - [Overview](https://www.systemsengineering.com/software-services/)
    - [Application Development](https://www.systemsengineering.com/software-services/application-development/)
    - [SharePoint](https://www.systemsengineering.com/software-services/sharepoint/)
    - [Database Services](https://www.systemsengineering.com/software-services/database-services/)
- IT Security 
    - [Overview](https://www.systemsengineering.com/security/)
    - [Adaptive Cybersecurity Framework (aCSF)](https://www.systemsengineering.com/se-adaptive-cybersecurity-framework-acsf/)
    - Cloud Security 
          - [Service Overview](https://www.systemsengineering.com/security/cloud-security/)
          - [Cloud Security Resources](https://www.systemsengineering.com/security/cloud-security/cloud-security-resources/)
    - [Security Awareness Training](https://www.systemsengineering.com/security/security-awareness-training/)
    - [Cybersecurity Risk Assesment](https://www.systemsengineering.com/security/cybersecurity-risk-assessment/)
- Compliance 
    - [Overview](https://www.systemsengineering.com/compliance/)
    - [Cybersecurity Maturity Model Certification (CMMC)](https://www.systemsengineering.com/compliance/cmmc-compliance/) 
          - [CMMC Compliance Service](https://www.systemsengineering.com/compliance/cmmc-compliance/cmmc-compliance-service/)
          - [CMMC Gap Analysis](https://www.systemsengineering.com/compliance/cmmc-compliance/cmmc-gap-analysis/)
          - [CMMC Resources Hub](https://www.systemsengineering.com/compliance/cmmc-compliance/cmmc-resources/)
    - [National Credit Union Administration (NCUA)](https://www.systemsengineering.com/compliance/ncua/)
- Cloud Services 
    - [Overview](https://www.systemsengineering.com/cloud-services/)
    - [Cloud Management](https://www.systemsengineering.com/cloud-services/cloud-management/)
    - [Cloud Security](https://www.systemsengineering.com/cloud-services/cloud-migration/)
    - Office 365 
          - [Office 365 Migration & Support](https://www.systemsengineering.com/cloud-services/office-365-migration-support/)
          - [Office 365 Backup](https://www.systemsengineering.com/cloud-services/office-365-migration-support/office-365-backup/)
    - [Cloud Assessment](https://www.systemsengineering.com/cloud-services/cloud-assessment/)
- Industries 
    - [Overview](https://www.systemsengineering.com/industries/)
    - [Construction](https://www.systemsengineering.com/industries/construction/)
    - [Education](https://www.systemsengineering.com/industries/education/)
    - [Financial Services](https://www.systemsengineering.com/industries/financial-services/) 
          - [Banks](https://www.systemsengineering.com/industries/financial-services/banks/)
          - [Credit Unions](https://www.systemsengineering.com/industries/financial-services/credit-unions/)
          - [Accountants & Wealth Managers](https://www.systemsengineering.com/industries/financial-services/accountants-wealth-managers/)
    - [Government](https://www.systemsengineering.com/industries/government/)
    - [Healthcare](https://www.systemsengineering.com/industries/healthcare/)
    - [Legal](https://www.systemsengineering.com/industries/legal/)
    - [Manufacturers](https://www.systemsengineering.com/industries/manufacturers/)
    - [Nonprofits](https://www.systemsengineering.com/industries/nonprofits/)
- About 
    - [Overview](https://www.systemsengineering.com/about/)
    - [Leadership](https://www.systemsengineering.com/about/leadership/)
    - [Our Difference](https://www.systemsengineering.com/about/our-difference/)
    - [Employee-Owned](https://www.systemsengineering.com/about/esop/)
    - [Our Partners](https://www.systemsengineering.com/about/our-partners/)
    - Careers & Internships 
          - [Openings](https://www.systemsengineering.com/about/careers/)
          - [Benefits](https://www.systemsengineering.com/about/careers/benefits/)
          - [Internships](https://www.systemsengineering.com/about/careers/internships/)
    - [Culture](https://www.systemsengineering.com/culture/)
- [Case Studies](https://www.systemsengineering.com/case-studies/)
- [Blog](https://blog.systemsengineering.com/blog)
- [Events](https://www.systemsengineering.com/events/)
- [Client Center](https://www.systemsengineering.com/client-center/)
- [Contact](https://www.systemsengineering.com/about/contact/)

888.624.6737

[Email Us](mailto:info@systemsengineering.com)

![syse-blog-header](https://blog.systemsengineering.com/hs-fs/hubfs/Logos/syse-blog-header.jpg?width=1440&name=syse-blog-header.jpg "syse-blog-header")

# SE Guest Blog: Information Security Officer - It's not just a cool title

[![Share on facebook](https://blog.systemsengineering.com/hs-fs/hubfs/facebook-color.png?width=60&name=facebook-color.png)](http://www.facebook.com/share.php?u=https://blog.systemsengineering.com/blog/guest-blog-information-security-officer-its-not-just-a-cool-title&utm_medium=social&utm_source=facebook) [![Share on linkedin](https://blog.systemsengineering.com/hs-fs/hubfs/linkedin-color.png?width=60&name=linkedin-color.png)](http://www.linkedin.com/shareArticle?mini=true&url=https://blog.systemsengineering.com/blog/guest-blog-information-security-officer-its-not-just-a-cool-title&utm_medium=social&utm_source=linkedin) [![Share on email](https://blog.systemsengineering.com/hs-fs/hubfs/email-color.png?width=60&name=email-color.png)](mailto:?subject=Check%20out%20https://blog.systemsengineering.com/blog/guest-blog-information-security-officer-its-not-just-a-cool-title&utm_medium=social&utm_source=email%20&body=Check%20out%20https://blog.systemsengineering.com/blog/guest-blog-information-security-officer-its-not-just-a-cool-title&utm_medium=social&utm_source=email) 

 November 04, 2016 | Posted in:

[Compliance](https://blog.systemsengineering.com/blog/topic/compliance)

Posted by [Systems Engineering](https://blog.systemsengineering.com/blog/author/systems-engineering)

![TLoring.jpg](https://blog.systemsengineering.com/hs-fs/hubfs/blog-files/TLoring.jpg?width=125&name=TLoring.jpg "TLoring.jpg")The role of the Information Security Officer (ISO) varies based on the size and complexity of an organization. It may be a full or part-time position held by an employee having only ISO responsibilities or by an employee having other roles within the organization. A primary role of the ISO is to work with management to strengthen its information security program and to protect the organization’s information assets.

 The ISO contributes in the following ways:

- Defines and creates an Information security program,
- [Develops and implements information security policies, processes, and procedures that support the information security program](https://blog.syseng.com/blog/the-value-proposition-behind-good-security-practices),
- Performs independent reviews and audits of security activities and reports,
- And, identifies and communicates information security risks and mitigation strategies to the Board of Directors or senior management.

Independent reviews are a critical responsibility of the ISO to help ensure the adequacy and effectiveness of the organization’s efforts to manage information security. Typical activities and reports that are reviewed by the ISO include, but are not limited to, the following:

##### **Access**

- Reviews access to critical or sensitive files or databases: 
    - *Identifies critical and sensitive information and all methods to access and change that information.*
- Reviews high level privileges: 
    - *Investigates administrative access levels and log and monitor that access.*
- Reviews user account access changes: 
    - *Reviews added, modified, and removed users and access levels.*

##### **Policy Management**

- Reviews and oversees the [Vendor Management Program](https://blog.syseng.com/blog/the-value-proposition-behind-good-security-practices),
- Performs annual vendor reviews,
- Reviews security policy changes: 
    - *Reviews changes to Active Directory, password requirements, lockout parameters, and screen saver settings.*

##### **Physical and Environmental Security**

- Reviews infrastructure and equipment: 
    - *Verifies that uninterruptible power supplies (UPS) and generators are regularly tested, fire extinguishers and fire suppression systems are maintained, and alarm and environmental monitoring systems are regularly tested.*

##### **Event Logs**

- Reviews system event logs: 
    - *Reviews system events such as shutting down the system or starting/stopping a service, firewall and intrusion detection system (IDS)/intrusion prevention system (IPS) activity, antivirus reports, and successful or failed backups.*
- Reviews successful and failed authentication attempts: 
    - *Reviews remote access logs and all logins to network and critical applications to identify suspicious activity.*

##### **Security Procedures**

- Reviews Disaster Recovery (DR) and Incident Response (IR) Plans: 
    - *Reviews and updates the DR and IR plan, educate the organization’s employees on the DR plan and IR procedures, test the DR plan annually.* 

Independent reviews help the ISO to identify security risks and to communicate mitigation strategies to management. Understanding the role of the ISO within an organization and assigning appropriate responsibilities can be critical to the development, oversight, and management of information security within the organization.

 

---

*Tom Loring is a Manager of Macpage’s Information Assurance Services team, advising clients nationwide in the areas of IT and operational internal controls. Tom regularly performs SOC 1 and SOC 2 examinations, IT General Control Reviews, Information Risk Assessments, Cybersecurity Controls Reviews, and consulting for clients in a wide-variety of industries; including financial institutions, third-party data processors, statement printers, date centers and more. You can email Tom at [tjl@macpage.com](mailto:tjl@macpage.com). *

### Join the Conversation!

### Posts by Category

- [IT Solutions & Support (70)](https://blog.systemsengineering.com/blog/topic/it-solutions-support)
- [Announcements (64)](https://blog.systemsengineering.com/blog/topic/announcements)
- [Security Bulletins & Alerts (59)](https://blog.systemsengineering.com/blog/topic/security-bulletins-alerts)
- [Cybersecurity (55)](https://blog.systemsengineering.com/blog/topic/cybersecurity)
- [Business Transformation (30)](https://blog.systemsengineering.com/blog/topic/business-transformation)
- [Cloud Security (27)](https://blog.systemsengineering.com/blog/topic/cloud-security)
- [Workforce Enablement (21)](https://blog.systemsengineering.com/blog/topic/workforce-enablement)
- [Compliance (17)](https://blog.systemsengineering.com/blog/topic/compliance)
- [Network Security (13)](https://blog.systemsengineering.com/blog/topic/network-security)
- [Artificial Intelligence (10)](https://blog.systemsengineering.com/blog/topic/artificial-intelligence)

### Follow Us On Social

<https://www.linkedin.com/company/systemsengineering-> <https://twitter.com/sysengineering> <https://www.facebook.com/systemsengineeringinc>

### Contact Us

[888.624.6737](tel:888.624.6737)  
[info@systemsengineering.com](mailto:info@systemsengineering.com)

### Connect With Us

<https://www.linkedin.com/company/systemsengineering-> <https://www.facebook.com/systemsengineeringinc>

### Receive Our Blog

- [IT Services](https://www.systemsengineering.com/)
- [IT Security](https://www.systemsengineering.com/security/)
- [Compliance](https://www.systemsengineering.com/compliance/)
- [Cloud Services](https://www.systemsengineering.com/cloud-services/)
- [Industries](https://www.systemsengineering.com/industries/)
- [About](https://www.systemsengineering.com/about/)

- [Careers](https://www.systemsengineering.com/about/careers/)
- [White Papers](https://www.systemsengineering.com/white-papers/)
- [Case Studies](https://www.systemsengineering.com/case-studies/)
- [Blog](https://blog.systemsengineering.com/blog)
- [Events](https://www.systemsengineering.com/news-resources/events/)
- [Client Center](https://www.systemsengineering.com/client-center/)

![Ft-logo](https://blog.systemsengineering.com/hs-fs/hubfs/Ft-logo.png?width=105&name=Ft-logo.png)

 

 

888.624.6737 | [info@systemsengineering.com](mailto:info@systemsengineering.com)

Copyright 2025 Systems Engineering. All Rights Reserved. [Privacy Policy](https://www.systemsengineering.com/privacy-policy) [Support](https://www.systemsengineering.com/support/) [Trust Center](https://systems.app.ctrlmap.com/tp/trust/portal/links?puid=8010ba57-5a2e-40b4-9c56-2c18873c9e5f&trustPortalId=MQ==&code=4642)