1 / 1100%
The strategic planning process helps define the company's goals and how to achieve
them. Planning is the process of establishing long-term goals, determining the directions
and constraints to guide the tactical accomplishment of these goals, and identifying the
assets and capabilities the organization needs to achieve these goals. With a clear and
concise security strategic plan, managers, employees, and executives can see what is
expected of them, focus their efforts in the right direction, and know when their goals
have been achieved. Organizations that view strategic planning as unnecessary or
impractical are less likely to manage information risk effectively (Evans, 1).
Information security strategic planning can assist an organization in mitigating,
transferring, accepting, or avoiding information risk related to people, processes, and
technologies. Complying with industry standards, avoiding a damaging security incident,
maintaining the business's reputation, and supporting commitments to shareholders,
customers, partners, and suppliers are some of the benefits of an adequate information
security strategic plan.
Strategic planning for information security could include the following topics:
Students also viewed