Member-only story
Developing your Security Program: Part 2 — Developing your Security Program
In Part One of this series, we discussed meeting the stakeholders of your new program. This part of the series “Developing your Security Program” will discuss the approach to take as you develop your program.
The below image describes a great approach to strategically developing your security program. This method can be used whether you are going into a program and developing your strategy for your new role or if you are looking to transform your existing security program.
The first thing to note is that you want to focus on the business mission and help enable the business to achieve its goals. The outer ring depicts the various stages of developing or transforming your security program. The inner circle will show some of the potential impacts of your security program on the business.
Stage 1 — Strategic Framework — Select a framework that will act as the foundation of your security program and create a common language in which you can communicate with the business and have a similar lexicon in documenting the baseline requirements as well as the recommended additional protections to mitigate business risk. Note that there are frameworks that operate at several levels, at the enterprise level, at the program level, and the controls or implementation level. You will…
