A strategy is a plan to reach long-term goals. An information security strategy describes how the security program will support business objectives over the next few years, and it starts from the business, not from technology. The manager needs the business strategy, risk appetite, legal obligations and major initiatives in hand before writing anything. A strategy that could belong to any company, full of generic goals such as 'improve security posture', usually means this step was skipped.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.