There has been considerable effort spent over the decades to achieve a clear separation between the CIO and CISO roles. However, this separation creates inefficiency in the organization, and attempts to separate what is essentially one logical entity—Information Security. This session will start a discussion on the pros and cons of such an approach and propose an integrated approach to security program management.