1 / 1100%
 Strategic planning allows an organization to answer what is important to them and
what is needed to obtain goals. Strategic planning manifests itself as a document
that should be known to the company and serves as a guide for more tactical
planning. Organizations should include their position on information security within
their strategic plan. Having information security in the strategic plan makes it easier
to fit in every step of the organization's procedures and create a security concision
organization. Furthermore, it highlights the value of being security conscious by
illustrating how information security and business objectives converge (Stallings,1).
The strategic plan should clarify the company's risk tolerance and how security
meets the strategic needs of the business.
  The popularization of virtual containers and networks has introduced the need to
include virtualization security in a comprehensive security strategy. It is essential to
realize the benefits and the added complexities that visualized security gives to a
company. First, visualized protection is cost-effective as it doesn’t depend on
multiple hardware solutions that could cost thousands of dollars per dedicated
server. Second, it allows for flexibility by giving administrators tools to create
traditional firewalls, “insert security controls (such as encryption) between the
application layer and the underlying infrastructure, or use strategies such as micro-
segmentation to reduce the potential attack surface.”(2). The third is efficiency, due
to how fast teams can write templates and have each type of environment scale
according to the need. Virtualization, in general, presents a slew of new threats to
companies. One such vulnerability is the possibility of VM sprawl when VMs are left
running unintentionally, left unlatched, and vulnerable to threats. Companies can
leverage their strategic plan to combat vulnerabilities through virtualization by
asserting basic security principles applicable to all technology, such as implementing
the least privilege and reducing attack surfaces. Again, the strategic plan shouldn’t
have specifics on implementing these controls but should give everyone in the
company what ideals they should work with to carry out their day-to-day tasks.
Resources:
1. Stallings, W. (2018). Effective Cybersecurity. Pearson Technology
Group.https://strayer.vitalsource.com/books/9780134772950
2.No author, What is virtualized
security?https://www.vmware.com/topics/glossary/content/virtualized-
security.html#:~:text=Virtualized%20security%2C%20or%20security
%20virtualization,firewalls%2C%20routers%2C%20and%20switches.
Students also viewed