
Goal: Establish the prerequisites necessary for the proper implementation of the information security program.
- Business Missions & Objectives
- Stakeholder Buy-In
- Executive Sponsorship
- Roles & Responsibilities
- Steering Committee
- Budget Authority
- SWOT Analysis
- PESTLE Analysis
- Business Impact Assessment (BIA)
- Risk Management
- Risk Assessment
- Risk Reporting & Prioritization
- Risk Responses & Countermeasure Selection
- State of Applicability (SoA)
- Risk & Control Owners
- Gap Analysis (Current State vs. Desired State)
- Build vs. Buy vs. Partner
- Business Case
- Security Roadmap
- Plan of Actions & Milestones (POA&M)
- SMART Objectives
- Metrics & Key Indicators (KPIs, KRIs, KGIs)
