Information security strategy and plan
An information security strategy is a set of actions to achieve the security objectives. The strategy includes what should be done, how it should be done, and when it should be done in order to achieve the security objectives.
The strategy is basically a road map of specific actions required to achieve the objective. Based on the strategy, long- and short-term plans are finalized.
The prime objective of any security strategy is to support the business's objectives. An information security strategy should be aligned with a particular business's objectives. The first step for an information security manager in creating a plan is to understand and evaluate the business strategy. This is essential to align the information security strategy and plan with business strategy.
A strategic plan should include the desired state of information security. A strategy is considered to be effective if control objectives are met. The final responsibility...