Hello! Just received my CISSP in January and am a first-time poster and glad to be part of the community. I'm fairly new to a mid-size healthcare organization where I manage our security team. Previous to my coming on, security was run out of the IT Infrastructure team and reported up through the CIO. About a year before I started security was segregated out of IT as it's own team reporting up through the CFO. My experience before this job was in IT Infrastructure where all security duties were the responsibility of Infrastructure with no distinct security team.
As I now manage a distinct security team, there are some areas of responsibility that are gray to me. I'm sure that the answer depends on the circumstances of the organization but I'm wondering if there are any best practices around separation of duties between IT (specifically Infrastructure) and security? As some background, our IT team does have a distinct GRC/Audit function and operations function. Some examples that are gray to me are: IDS/IPS on the firewall, firewall rules, Anti-Virus/Malware administration, OS/ISO hardening, GPO administration, and patching. Should security play and advisory/audit function only in these areas or take ownership of some of them? Thanks in advance for the feedback!