Requirement:
A cybersecurity strategy must be defined, documented and approved. It must be supported by the head of the organization or his/her delegate (referred to in this document as Authorizing Official). The strategy goals must be in-line with related laws and regulations.
Control Implementation Guidelines:
- Conduct a workshop with stakeholders in the organization to align the objectives of the cybersecurity strategy with the organization's strategic objectives.
- Develop and document cybersecurity the strategy of the organization in order to align the organization's cybersecurity strategic objectives with related laws and regulations, including but not limited to (CCC, CSCC). A cybersecurity strategy often includes the following:
- Vision
- Mission
- Strategic Objectives
- Strategy Implementation Plan
- Projects
- Initiatives
- In order for the cybersecurity strategy of the organization to be effective, the approval of the representative must be based on the authority matrix approved by the organization
Relevant Cybersecurity Tools:
- All cybersecurity strategy models and roadmap
Expected Deliverables:
- The cybersecurity strategy document approved by the organization (electronic copy or official hard copy).
- Initiatives and projects included in the cybersecurity strategy of the organization.
Quick & Simple
Discover Our Cybersecurity Compliance Solutions:
Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you