From the course: Certified Information Systems Auditor (CISA) Cert Prep

Unlock this course with a free trial

Join today to access over 23,300 courses taught by industry experts.

Information security strategy

Information security strategy

- [Instructor] Now moving right along, let's go ahead and take a look at strategic planning. So this is a critical part of what our governing entities do for us, is they help us take those stakeholder needs, goals and objectives and turn them into strategy. So we've got a definition here from ISACA, which is obviously very relevant since ISACA oversees the CISA exam. So in information security and risk management, so you hear ISRM all the time, provides an organization with a roadmap. So a general direction, not every little specific step along the way, but if I'm going from North Carolina to California, I'm going to get on I-40 and I'm going to drive on I-40 through a bunch of states. But not every little step, every little speed limit, every little exit. So strategy's going to be broad, right? And it's going to have the goals and objectives to make sure that we align our information security program to the business goals of the organization, right? And that's everything. That's what…

Contents