StudyToCert

All certifications / CISM / Lessons

ISACA Certified Information Security Manager (CISM) 2026 exam content outline · Domain 1: Information security governance

Information security strategy: current state, desired state and gap analysis

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

A strategy is a plan to reach long-term goals. An information security strategy describes how the security program will support business objectives over the next few years, and it starts from the business, not from technology. The manager needs the business strategy, risk appetite, legal obligations and major initiatives in hand before writing anything. A strategy that could belong to any company, full of generic goals such as 'improve security posture', usually means this step was skipped.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISM for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISM study plan