Problem:
Question 1: Should your information technology department and information security department report to the same department head? Or, should your IT and IS department function separately? Why or why not?
Question 2: What is split knowledge, separation of duties, and mandatory vacations and why should these administrative countermeasures be part of your normal security operational procedures?
Please do not provide cut and paste answers and please include a source.