H. Security Strategy Development. Flashcards
What is a strategy
A plan to achieve an objective
What is the concept of strategy
Understand where you are now and where you want to be. The strategy is the path to follow to get from where you are (current state) to where you want to be (strategic objective).
What is an objective
A desired future state for the organization’s security posture and level of risk.
Strategic alignment - an objective of a strategy
The desired future state, and the strategy to get there, must be in alignment with the organization and its strategy and objectives.
Effective risk management - an objective of a strategy
A security program must include a risk management policy, processes, and procedures. Without risk management, decisions are made blindly without regard to their consequences or level of risk
Value delivery - an objective of a strategy
The desired future state of a security program should include a focus for continual improvement and increasing efficiency.
Resource optimization - an objective of a strategy
strategic goals should efficiently utilize available resources.
Performance measurement - an objective of a strategy
the ongoing security and security-related business operations should themselves be measurable,
Assurance process integration - an objective of a strategy
An effective strategy would work to break down these silos and consolidate assurance processes, reducing hidden risks.