Developing Information Security Strategy
Gathering Input
Last Updated: March 24, 2026Security program objectives should be established and validated by key stakeholders at the start of strategy planning and during roadmap approval. An organization security steering...
Defining Information Security Capabilities
Last Updated: March 9, 2026An effective information security strategy does not begin with technology and it does not end with compliance. It begins with a clear understanding of the...
Stakeholder Engagement and Requirement Traceability
Last Updated: March 9, 2026A security strategy that cannot demonstrate a clear and auditable connection between its objectives, the gaps it has identified, and the specific initiatives designed to...
Principle of Subsidiarity in Information Security
Last Updated: March 9, 2026The Principle of Subsidiarity is a governance philosophy that emphasizes enabling decisions to be made as locally as possible, while ensuring alignment with central governance...
Strategic Priority: Adopting a Risk-Based Approach
Last Updated: March 9, 2026The management of cyber risk is undergoing a fundamental transition, moving away from maturity-based approaches that measure progress against predefined capability milestones toward risk-based methodologies...
Strategic Priority: Security Awareness and Culture
Last Updated: March 9, 2026One of the most consequential and frequently underestimated decisions an organisation makes in developing its information security strategy is how seriously it treats the human...
Strategic Priority: Technology Risk Management
Last Updated: March 9, 2026A security strategy that does not explicitly address its relationship to the organisation’s technology risk management programme is structurally incomplete. Technology risk is not a...
Strategic Priority: Third Party Risk Management
Last Updated: March 9, 2026The security perimeter of a modern organisation does not end at the boundary of its own operations. Every supplier, vendor, service provider, and business partner...
Strategic Priority: Attack Surface Management
Last Updated: March 9, 2026An information security strategy that does not explicitly address how the organisation will discover, understand, and continuously manage its attack surface is a strategy built...
Strategic Priority: Defining and Structuring the IS Organisation
Last Updated: March 9, 2026The structure of the information security organisation is one of the most consequential governance decisions an organisation makes. A well-constructed security organisation ensures that the...
