226 SOFTWARE QUALITY ASSURANCE
Organizational Security Organizational security control addresses the
need for a management framework that creates, sustains, and man-
ages the security infrastructure, including the following:
Management information security forum—provides a multidis-
ciplinary committee chartered to discuss and disseminate
information security issues throughout the organization
Information system security ocer (ISSO)—acts as a central point
of contact for information security issues, direction, and
decisions
Information security responsibilities—individual information secu-
rity responsibilities are unambiguously allocated and detailed
within job descriptions
Authorization processes—ensures that security considerations are
evaluat ...