Skip to the content Skip to the Navigation
CyberLadder.io
  • Home
  • Background
  • The Framework
    • Introduction
    • Stage 1: Identify & Document
    • Stage 2: Plan
    • Stage 3: Implement
    • Stage 4: Test, Monitor, and Educate
  • Threats & Attacks
  • Common Mistakes
  • Case Studies

Stage 2: Plan

  1. HOME
  2. Stage 2: Plan
Goal: Establish the prerequisites necessary for the proper implementation of the information security program.
  1. Business Missions & Objectives
  2. Stakeholder Buy-In
  3. Executive Sponsorship
  4. Roles & Responsibilities
  5. Steering Committee
  6. Budget Authority
  7. SWOT Analysis
  8. PESTLE Analysis
  9. Business Impact Assessment (BIA)
  10. Risk Management
  11. Risk Assessment
  12. Risk Reporting & Prioritization
  13. Risk Responses & Countermeasure Selection
  14. State of Applicability (SoA)
  15. Risk & Control Owners
  16. Gap Analysis (Current State vs. Desired State)
  17. Build vs. Buy vs. Partner
  18. Business Case
  19. Security Roadmap
  20. Plan of Actions & Milestones (POA&M)
  21. SMART Objectives
  22. Metrics & Key Indicators (KPIs, KRIs, KGIs)

An UMPI Capstone Project
More About UMPI

Homepage

Cybersecurity Program

YourPace Programs

Apply

Further Reading

NIST Cybersecurity Framework

MITRE ATT&CK

CISA Homepage

Center for Internet Security (CIS)

ISO/IEC 27001:2022

Copyright © CyberLadder.io All Rights Reserved.

Powered by WordPress & Lightning Theme by Vektor,Inc. technology.

MENU
  • Home
  • Background
  • The Framework
    • Introduction
    • Stage 1: Identify & Document
    • Stage 2: Plan
    • Stage 3: Implement
    • Stage 4: Test, Monitor, and Educate
  • Threats & Attacks
  • Common Mistakes
  • Case Studies