An information security strategy is a plan to mitigate risks while complying with legal, statutory, contractual and policy requirements.
A defined strategy will serve to ensure a standard methodology of risk management throughout an organisation.
Typical steps include the definition of control objectives, a baseline level of protection, risk assessment ans selection of mitigating controls, followed by the establishment of benchmarks and metrics, and ongoing audit and review.
The level of protection should match the value of the resources being protected.
Security costs can vary greatly, so too high a level of security relative to the value of the resource is an unnecessary expense, while too low a level of security relative to the value of the resource results in inadequate security.
AUDIT MANAGEMENT BUDGET CONTROL BUSINESS CONTINUITY LIABILITY RISK ASSESSMENT