Executing a Security Program
Operationalising the Information Security Strategy
Last Updated: March 9, 2026A well-constructed information security strategy defines what the organisation must achieve. The security program defines how it will get there. The program is the operational...
Managing the Security Program
Last Updated: March 9, 2026The security program represents one of the most complex and consequential delivery undertakings an organisation will manage. It spans multiple departments, involves significant financial investment,...
Identify Applicable Information Security Controls
Last Updated: March 9, 2026With the regulatory frameworks and security standards selected during the strategy phase, the security program moves into the operational discipline of translating those framework selections...
Addressing Identified Risks
Last Updated: March 9, 2026The risk assessment conducted during the strategy phase produces a structured and prioritised understanding of the threats facing the organisation, the vulnerabilities those threats could...
Aligning with Situational Awareness
Last Updated: March 9, 2026Effective risk management begins with a thorough and continuously maintained understanding of the environment that the security program is designed to protect. Without accurate knowledge...
Managing Resources
Last Updated: March 9, 2026The successful delivery of a security program depends as much on the people executing it as on the quality of its design. Governance frameworks, risk...
Mapping Security Strategy Goals to Incident Response
Last Updated: March 9, 2026A security program that is not explicitly connected to the goals established in the security strategy is a program that operates without direction. One of...
Build Cyber Resilience
Last Updated: March 9, 2026Security programs that are designed exclusively around the prevention of security incidents reflect a fundamentally incomplete understanding of the threat environment in which modern organisations...
