Creating your future roadmap
Now that we have gone through the analysis of our current state and scored ourselves based on the scoring model found in Table 11.2, we should now begin to determine our future state. The future state is where we plan to be in the next three to five years. Not only will we need to take a risk-based approach to how we develop our strategies, but we also need to ensure that the goals we put forward are attainable.
First and foremost, you need to look at how you can reduce the largest amount of risk with the least amount of effort. It is not because you are lazy; rather, it is because you are trying to reduce the biggest amount of risk possible with the least amount of resources. This could be introducing a new password standard, writing new policies, or developing architectural drawings.
The longer-termed projects, such as introducing multifactor authentication (MFA), integrating all applications with single sign-on, or introducing a new logging standard...