Key information security program plan elements
Now that you have gathered the information needed to properly rightsize and establish the vision for your information security program, it is time to begin establishing your plan. The information security program plan is a management document for the information security professional to establish key decisions and planning information as it relates to the execution of the information security program.
Develop your information security program strategy
To ensure that you are developing a holistic business-aligned information security program, you need to take the time to establish an information security program strategy. You should establish clear and concise strategy goals that will help you in your future program planning.
Examples of strategic goals your organization can use include:
- Information security risk assessment: Provide for the periodic review of information security risks and implement appropriate responses
- Information security governance...