SlideShare a Scribd company logo
1 of 26
Strategy and Strategic Planning:
Strategy, Strategic planning and security
strategy, the information security lifecycle
and Architecting the enterprise
 The Role of Planning
 Precursors to Planning
 Values Statement
 Vision Statement
 Mission Statement
 Strategic Planning
 Creating a Strategic Plan
 Planning Levels
 Planning and the CISO(Chief Info Security Officer)
 Planning for Information Security Implementation
 Identify the roles in organizations that are active in the
planning process
 Grasp the principal components of information security
system implementation planning in the organizational
planning scheme.
Planning Influences
 Employees
 Management
 Stockholders
 Outside stakeholders
 Physical environment
 Political and legal environment
 Competitive environment
 Technological environment
6
Information Security Professionals
 Professionals that support the information
security program
 Chief Information Officer (CIO)
 Chief Information Security Office (CISO)
 Security Managers
 Security Technicians
 Data Owners
 Data Custodians
 Data Users
Slide 6
7
Planning Definition
 Planning is creating action steps toward goals
and then controlling them
 Provides direction for the organization’s future
 Allows managing resources
 Optimizes the use of the resources
 Coordinates the effort of independent
organizational units
8
Precursors to Planning
 Values Statement
 Vision Statement
 Mission Statement
9
Values Statement
 Principles
 Qualities
 Benchmarks
 What your company is?
 Microsoft: Integrity, honesty, passion, and
respectfulness are significant parts of
Microsoft’s corporate philosophy
10
Vision Statement
 Ambitious
 Best-case scenario
 Future goals
 Where your company wants to be?
 Microsoft: A personal computer in every
home running Microsoft software
11
Mission Statement
 Organization’s business
 Areas of operation
 Internal
 External
 How your company is going to get there?
 Google: Organize the world's information and
make it universally accessible and useful.
12
Strategic Planning
 Strategy lays out the long-term direction to be
taken by organization
 It guides organizational efforts, and focuses
resources toward specific, clearly defined
goals.
 Strategic planning includes
 Mission statement
 Vision statement
 Values statement
 Coordinated plans for sub units
13
Creating a Strategic Plan
 Organization
 Develops a general strategy
 Creates specific strategic plans for major divisions
 Each level of translates those objectives into
more specific objectives for the level below
14
Top-Down Strategic Planning
15
Creating a Strategic Plan
 Strategic goals are translated into tasks
 Specific
 Measurable
 Achievable
 Realistic
 Timely
16
Planning Levels
 Strategic Planning
 Five or more year focus
 Strategic plan separated into strategic goals for each
department
 Tactical Planning
 One to three year focus
 Breaks strategic goals into a series of incremental
objectives
17
Planning Levels
 Operational Planning
 Organize the ongoing, day-to-day performance of
tasks
 Includes clearly identified coordination activities
across department boundaries
 Communications requirements
 Weekly meetings
 Summaries
 Progress reports
18
Planning Levels
19
Strategic Plan Elements
 Introduction by senior executive
 Executive Summary
 Mission Statement and Vision Statement
 Organizational Profile and History
 Strategic Issues and Core Values
 Program Goals and Objectives
 Management/Operations Goals and Objectives
 Appendices (optional)
 Strengths, weaknesses, opportunities and threats (SWOT)
analyses, surveys, budgets &etc
20
10 Tips For Strategic Planning
1. Create a compelling vision statement
2. Embrace the use of balanced scorecard approach
3. Deploy a draft high level plan early, and get input
from stakeholders
4. Make the evolving plan visible
21
10 Tips For Planning (cont.)
5. Make the process invigorating for everyone
6. Be persistent
7. Make the process continuous
8. Provide meaning
9. Be yourself
10. Have fun
22
Planning For InfoSec
Implementation
 Commonly the CISO directly reports to the
CIO.
 The CIO and CISO play important roles in
translating overall strategic planning into
tactical and operational information security
plans
 CISO plays a more active role planning the
details
23
CISO Job Description
 Creates strategic information security plan with a vision
for the future of information security
 Understands fundamental business activities performed
by the company
 Suggests appropriate information security solutions that
uniquely protect these activities
 Improves status of information security by developing
 action plans
 schedules
 budgets
 status reports
 top management communications
24
Planning for Information Security
 CIO: translates strategic plan into departmental and
InfoSec objectives
 CISO: translates InfoSec objectives into tactical and
operational objectives
 Implementation can now begin
 Implementation of information security can be
accomplished in two ways
 Bottom-up
 Top-down
25
Bottom-Up Approach
 Grass-roots effort
 Individual administrators try to improve
security
 No coordinated planning from upper
management
 No coordination between departments
 Unpredictable funding
26
Top-Down Approach
 Strong upper management support
 A dedicated champion
 Assured funding
 Clear planning and implementation process
 Ability to influence organizational culture

More Related Content

Similar to unit 3.pptx

Chapter 12IT Strategy and Balanced ScorecardPrepared b.docx
Chapter 12IT Strategy and Balanced ScorecardPrepared b.docxChapter 12IT Strategy and Balanced ScorecardPrepared b.docx
Chapter 12IT Strategy and Balanced ScorecardPrepared b.docx
keturahhazelhurst
 
Chapter 12IT Strategy and Balanced ScorecardPrepared b.docx
Chapter 12IT Strategy and Balanced ScorecardPrepared b.docxChapter 12IT Strategy and Balanced ScorecardPrepared b.docx
Chapter 12IT Strategy and Balanced ScorecardPrepared b.docx
zebadiahsummers
 
Chapter 12IT Strategy and Balanced ScorecardPrepared b.docx
Chapter 12IT Strategy and Balanced ScorecardPrepared b.docxChapter 12IT Strategy and Balanced ScorecardPrepared b.docx
Chapter 12IT Strategy and Balanced ScorecardPrepared b.docx
cravennichole326
 
Strategic Planning: Eight Steps To Implementation
Strategic Planning: Eight Steps To ImplementationStrategic Planning: Eight Steps To Implementation
Strategic Planning: Eight Steps To Implementation
Operational Excellence Consulting
 
Developing an IT Scorecard Using the Balanced Scorecard Approach
Developing an IT Scorecard  Using the Balanced Scorecard ApproachDeveloping an IT Scorecard  Using the Balanced Scorecard Approach
Developing an IT Scorecard Using the Balanced Scorecard Approach
Senaka Ariyasinghe
 

Similar to unit 3.pptx (20)

How To Balance Long-term Strategic Goals With Immediate Operating Concerns, R...
How To Balance Long-term Strategic Goals With Immediate Operating Concerns, R...How To Balance Long-term Strategic Goals With Immediate Operating Concerns, R...
How To Balance Long-term Strategic Goals With Immediate Operating Concerns, R...
 
Book Gis ROI Presentation
Book   Gis ROI PresentationBook   Gis ROI Presentation
Book Gis ROI Presentation
 
Strategic Planning: 10 Effective Keys for Successful Implementation | Future ...
Strategic Planning: 10 Effective Keys for Successful Implementation | Future ...Strategic Planning: 10 Effective Keys for Successful Implementation | Future ...
Strategic Planning: 10 Effective Keys for Successful Implementation | Future ...
 
Chapter 12IT Strategy and Balanced ScorecardPrepared b.docx
Chapter 12IT Strategy and Balanced ScorecardPrepared b.docxChapter 12IT Strategy and Balanced ScorecardPrepared b.docx
Chapter 12IT Strategy and Balanced ScorecardPrepared b.docx
 
Chapter 12IT Strategy and Balanced ScorecardPrepared b.docx
Chapter 12IT Strategy and Balanced ScorecardPrepared b.docxChapter 12IT Strategy and Balanced ScorecardPrepared b.docx
Chapter 12IT Strategy and Balanced ScorecardPrepared b.docx
 
Chapter 12IT Strategy and Balanced ScorecardPrepared b.docx
Chapter 12IT Strategy and Balanced ScorecardPrepared b.docxChapter 12IT Strategy and Balanced ScorecardPrepared b.docx
Chapter 12IT Strategy and Balanced ScorecardPrepared b.docx
 
Strategic Planning: Eight Steps To Implementation
Strategic Planning: Eight Steps To ImplementationStrategic Planning: Eight Steps To Implementation
Strategic Planning: Eight Steps To Implementation
 
pappu mgmt
pappu mgmtpappu mgmt
pappu mgmt
 
planningworkactivitiesch8-211028154822.pptx
planningworkactivitiesch8-211028154822.pptxplanningworkactivitiesch8-211028154822.pptx
planningworkactivitiesch8-211028154822.pptx
 
Enkkhancing Our Strategic Execution Culture (EOSEC)_Facilitator Guide_V1.0_20...
Enkkhancing Our Strategic Execution Culture (EOSEC)_Facilitator Guide_V1.0_20...Enkkhancing Our Strategic Execution Culture (EOSEC)_Facilitator Guide_V1.0_20...
Enkkhancing Our Strategic Execution Culture (EOSEC)_Facilitator Guide_V1.0_20...
 
Integrating Strategy to Operational Execution
Integrating Strategy to Operational ExecutionIntegrating Strategy to Operational Execution
Integrating Strategy to Operational Execution
 
Project integration management ch 4
Project integration management ch 4Project integration management ch 4
Project integration management ch 4
 
Developing an IT Scorecard Using the Balanced Scorecard Approach
Developing an IT Scorecard  Using the Balanced Scorecard ApproachDeveloping an IT Scorecard  Using the Balanced Scorecard Approach
Developing an IT Scorecard Using the Balanced Scorecard Approach
 
Insight into Security Leader Success Part 2
Insight into Security Leader Success Part 2Insight into Security Leader Success Part 2
Insight into Security Leader Success Part 2
 
Methodology for sustainability strategic planning and management
Methodology for sustainability strategic planning and managementMethodology for sustainability strategic planning and management
Methodology for sustainability strategic planning and management
 
Developing IT Strategy
Developing IT StrategyDeveloping IT Strategy
Developing IT Strategy
 
Post Merger Integration Toolkit - Overview and 3-Phase Approach.pptx
Post Merger Integration Toolkit - Overview and 3-Phase Approach.pptxPost Merger Integration Toolkit - Overview and 3-Phase Approach.pptx
Post Merger Integration Toolkit - Overview and 3-Phase Approach.pptx
 
Building a Strategy Focused IT Organization using Balanced Scorecard
Building a Strategy Focused IT Organization using Balanced ScorecardBuilding a Strategy Focused IT Organization using Balanced Scorecard
Building a Strategy Focused IT Organization using Balanced Scorecard
 
9 Competencies Your Project Manager Needs to Succeed | IPM.pdf
9 Competencies Your Project Manager Needs to Succeed | IPM.pdf9 Competencies Your Project Manager Needs to Succeed | IPM.pdf
9 Competencies Your Project Manager Needs to Succeed | IPM.pdf
 
Cooper Untech10 IT Program Mgmt Final
Cooper Untech10 IT Program Mgmt FinalCooper Untech10 IT Program Mgmt Final
Cooper Untech10 IT Program Mgmt Final
 

Recently uploaded

UNIT-V FMM.HYDRAULIC TURBINE - Construction and working
UNIT-V FMM.HYDRAULIC TURBINE - Construction and workingUNIT-V FMM.HYDRAULIC TURBINE - Construction and working
UNIT-V FMM.HYDRAULIC TURBINE - Construction and working
rknatarajan
 
Structural Analysis and Design of Foundations: A Comprehensive Handbook for S...
Structural Analysis and Design of Foundations: A Comprehensive Handbook for S...Structural Analysis and Design of Foundations: A Comprehensive Handbook for S...
Structural Analysis and Design of Foundations: A Comprehensive Handbook for S...
Dr.Costas Sachpazis
 
Call for Papers - Educational Administration: Theory and Practice, E-ISSN: 21...
Call for Papers - Educational Administration: Theory and Practice, E-ISSN: 21...Call for Papers - Educational Administration: Theory and Practice, E-ISSN: 21...
Call for Papers - Educational Administration: Theory and Practice, E-ISSN: 21...
Christo Ananth
 

Recently uploaded (20)

KubeKraft presentation @CloudNativeHooghly
KubeKraft presentation @CloudNativeHooghlyKubeKraft presentation @CloudNativeHooghly
KubeKraft presentation @CloudNativeHooghly
 
Call Girls Service Nagpur Tanvi Call 7001035870 Meet With Nagpur Escorts
Call Girls Service Nagpur Tanvi Call 7001035870 Meet With Nagpur EscortsCall Girls Service Nagpur Tanvi Call 7001035870 Meet With Nagpur Escorts
Call Girls Service Nagpur Tanvi Call 7001035870 Meet With Nagpur Escorts
 
UNIT-V FMM.HYDRAULIC TURBINE - Construction and working
UNIT-V FMM.HYDRAULIC TURBINE - Construction and workingUNIT-V FMM.HYDRAULIC TURBINE - Construction and working
UNIT-V FMM.HYDRAULIC TURBINE - Construction and working
 
UNIT-II FMM-Flow Through Circular Conduits
UNIT-II FMM-Flow Through Circular ConduitsUNIT-II FMM-Flow Through Circular Conduits
UNIT-II FMM-Flow Through Circular Conduits
 
Call Girls Pimpri Chinchwad Call Me 7737669865 Budget Friendly No Advance Boo...
Call Girls Pimpri Chinchwad Call Me 7737669865 Budget Friendly No Advance Boo...Call Girls Pimpri Chinchwad Call Me 7737669865 Budget Friendly No Advance Boo...
Call Girls Pimpri Chinchwad Call Me 7737669865 Budget Friendly No Advance Boo...
 
(INDIRA) Call Girl Aurangabad Call Now 8617697112 Aurangabad Escorts 24x7
(INDIRA) Call Girl Aurangabad Call Now 8617697112 Aurangabad Escorts 24x7(INDIRA) Call Girl Aurangabad Call Now 8617697112 Aurangabad Escorts 24x7
(INDIRA) Call Girl Aurangabad Call Now 8617697112 Aurangabad Escorts 24x7
 
MANUFACTURING PROCESS-II UNIT-2 LATHE MACHINE
MANUFACTURING PROCESS-II UNIT-2 LATHE MACHINEMANUFACTURING PROCESS-II UNIT-2 LATHE MACHINE
MANUFACTURING PROCESS-II UNIT-2 LATHE MACHINE
 
Extrusion Processes and Their Limitations
Extrusion Processes and Their LimitationsExtrusion Processes and Their Limitations
Extrusion Processes and Their Limitations
 
Structural Analysis and Design of Foundations: A Comprehensive Handbook for S...
Structural Analysis and Design of Foundations: A Comprehensive Handbook for S...Structural Analysis and Design of Foundations: A Comprehensive Handbook for S...
Structural Analysis and Design of Foundations: A Comprehensive Handbook for S...
 
Booking open Available Pune Call Girls Pargaon 6297143586 Call Hot Indian Gi...
Booking open Available Pune Call Girls Pargaon  6297143586 Call Hot Indian Gi...Booking open Available Pune Call Girls Pargaon  6297143586 Call Hot Indian Gi...
Booking open Available Pune Call Girls Pargaon 6297143586 Call Hot Indian Gi...
 
Call Girls Service Nashik Vaishnavi 7001305949 Independent Escort Service Nashik
Call Girls Service Nashik Vaishnavi 7001305949 Independent Escort Service NashikCall Girls Service Nashik Vaishnavi 7001305949 Independent Escort Service Nashik
Call Girls Service Nashik Vaishnavi 7001305949 Independent Escort Service Nashik
 
Call for Papers - Educational Administration: Theory and Practice, E-ISSN: 21...
Call for Papers - Educational Administration: Theory and Practice, E-ISSN: 21...Call for Papers - Educational Administration: Theory and Practice, E-ISSN: 21...
Call for Papers - Educational Administration: Theory and Practice, E-ISSN: 21...
 
College Call Girls Nashik Nehal 7001305949 Independent Escort Service Nashik
College Call Girls Nashik Nehal 7001305949 Independent Escort Service NashikCollege Call Girls Nashik Nehal 7001305949 Independent Escort Service Nashik
College Call Girls Nashik Nehal 7001305949 Independent Escort Service Nashik
 
Coefficient of Thermal Expansion and their Importance.pptx
Coefficient of Thermal Expansion and their Importance.pptxCoefficient of Thermal Expansion and their Importance.pptx
Coefficient of Thermal Expansion and their Importance.pptx
 
Booking open Available Pune Call Girls Koregaon Park 6297143586 Call Hot Ind...
Booking open Available Pune Call Girls Koregaon Park  6297143586 Call Hot Ind...Booking open Available Pune Call Girls Koregaon Park  6297143586 Call Hot Ind...
Booking open Available Pune Call Girls Koregaon Park 6297143586 Call Hot Ind...
 
Glass Ceramics: Processing and Properties
Glass Ceramics: Processing and PropertiesGlass Ceramics: Processing and Properties
Glass Ceramics: Processing and Properties
 
Introduction to Multiple Access Protocol.pptx
Introduction to Multiple Access Protocol.pptxIntroduction to Multiple Access Protocol.pptx
Introduction to Multiple Access Protocol.pptx
 
Russian Call Girls in Nagpur Grishma Call 7001035870 Meet With Nagpur Escorts
Russian Call Girls in Nagpur Grishma Call 7001035870 Meet With Nagpur EscortsRussian Call Girls in Nagpur Grishma Call 7001035870 Meet With Nagpur Escorts
Russian Call Girls in Nagpur Grishma Call 7001035870 Meet With Nagpur Escorts
 
MANUFACTURING PROCESS-II UNIT-1 THEORY OF METAL CUTTING
MANUFACTURING PROCESS-II UNIT-1 THEORY OF METAL CUTTINGMANUFACTURING PROCESS-II UNIT-1 THEORY OF METAL CUTTING
MANUFACTURING PROCESS-II UNIT-1 THEORY OF METAL CUTTING
 
Introduction to IEEE STANDARDS and its different types.pptx
Introduction to IEEE STANDARDS and its different types.pptxIntroduction to IEEE STANDARDS and its different types.pptx
Introduction to IEEE STANDARDS and its different types.pptx
 

unit 3.pptx

  • 1. Strategy and Strategic Planning: Strategy, Strategic planning and security strategy, the information security lifecycle and Architecting the enterprise
  • 2.  The Role of Planning  Precursors to Planning  Values Statement  Vision Statement  Mission Statement  Strategic Planning  Creating a Strategic Plan  Planning Levels  Planning and the CISO(Chief Info Security Officer)  Planning for Information Security Implementation
  • 3.  Identify the roles in organizations that are active in the planning process  Grasp the principal components of information security system implementation planning in the organizational planning scheme.
  • 4.
  • 5. Planning Influences  Employees  Management  Stockholders  Outside stakeholders  Physical environment  Political and legal environment  Competitive environment  Technological environment
  • 6. 6 Information Security Professionals  Professionals that support the information security program  Chief Information Officer (CIO)  Chief Information Security Office (CISO)  Security Managers  Security Technicians  Data Owners  Data Custodians  Data Users Slide 6
  • 7. 7 Planning Definition  Planning is creating action steps toward goals and then controlling them  Provides direction for the organization’s future  Allows managing resources  Optimizes the use of the resources  Coordinates the effort of independent organizational units
  • 8. 8 Precursors to Planning  Values Statement  Vision Statement  Mission Statement
  • 9. 9 Values Statement  Principles  Qualities  Benchmarks  What your company is?  Microsoft: Integrity, honesty, passion, and respectfulness are significant parts of Microsoft’s corporate philosophy
  • 10. 10 Vision Statement  Ambitious  Best-case scenario  Future goals  Where your company wants to be?  Microsoft: A personal computer in every home running Microsoft software
  • 11. 11 Mission Statement  Organization’s business  Areas of operation  Internal  External  How your company is going to get there?  Google: Organize the world's information and make it universally accessible and useful.
  • 12. 12 Strategic Planning  Strategy lays out the long-term direction to be taken by organization  It guides organizational efforts, and focuses resources toward specific, clearly defined goals.  Strategic planning includes  Mission statement  Vision statement  Values statement  Coordinated plans for sub units
  • 13. 13 Creating a Strategic Plan  Organization  Develops a general strategy  Creates specific strategic plans for major divisions  Each level of translates those objectives into more specific objectives for the level below
  • 15. 15 Creating a Strategic Plan  Strategic goals are translated into tasks  Specific  Measurable  Achievable  Realistic  Timely
  • 16. 16 Planning Levels  Strategic Planning  Five or more year focus  Strategic plan separated into strategic goals for each department  Tactical Planning  One to three year focus  Breaks strategic goals into a series of incremental objectives
  • 17. 17 Planning Levels  Operational Planning  Organize the ongoing, day-to-day performance of tasks  Includes clearly identified coordination activities across department boundaries  Communications requirements  Weekly meetings  Summaries  Progress reports
  • 19. 19 Strategic Plan Elements  Introduction by senior executive  Executive Summary  Mission Statement and Vision Statement  Organizational Profile and History  Strategic Issues and Core Values  Program Goals and Objectives  Management/Operations Goals and Objectives  Appendices (optional)  Strengths, weaknesses, opportunities and threats (SWOT) analyses, surveys, budgets &etc
  • 20. 20 10 Tips For Strategic Planning 1. Create a compelling vision statement 2. Embrace the use of balanced scorecard approach 3. Deploy a draft high level plan early, and get input from stakeholders 4. Make the evolving plan visible
  • 21. 21 10 Tips For Planning (cont.) 5. Make the process invigorating for everyone 6. Be persistent 7. Make the process continuous 8. Provide meaning 9. Be yourself 10. Have fun
  • 22. 22 Planning For InfoSec Implementation  Commonly the CISO directly reports to the CIO.  The CIO and CISO play important roles in translating overall strategic planning into tactical and operational information security plans  CISO plays a more active role planning the details
  • 23. 23 CISO Job Description  Creates strategic information security plan with a vision for the future of information security  Understands fundamental business activities performed by the company  Suggests appropriate information security solutions that uniquely protect these activities  Improves status of information security by developing  action plans  schedules  budgets  status reports  top management communications
  • 24. 24 Planning for Information Security  CIO: translates strategic plan into departmental and InfoSec objectives  CISO: translates InfoSec objectives into tactical and operational objectives  Implementation can now begin  Implementation of information security can be accomplished in two ways  Bottom-up  Top-down
  • 25. 25 Bottom-Up Approach  Grass-roots effort  Individual administrators try to improve security  No coordinated planning from upper management  No coordination between departments  Unpredictable funding
  • 26. 26 Top-Down Approach  Strong upper management support  A dedicated champion  Assured funding  Clear planning and implementation process  Ability to influence organizational culture