The cybersecurity program strategy defines goals and objectives for the organization’s cybersecurity activities
In its simplest form, the cybersecurity program strategy should include a list of goals and objectives and at least a high-level plan for the actions, activities, and tasks that must be performed to meet them. These objectives should support the achievement and ongoing improvement of an appropriate cybersecurity posture and support the accomplishment of overall organizational strategic objectives. These are examples of a cybersecurity goal and related objectives: Goal: Minimize the impact of cybersecurity incidents on customers. Objectives: · Maintain commitment to customers by safeguarding their sensitive information from cyber risk and responding competently and appropriately to minimize impact when incidents occur. · Support the availability of services through the quick detection of cybersecurity incidents that may lead to service interruptions and by expeditiously responding to those events.
Related Practices · Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: PROGRAM-1a, PROGRAM-1b, PROGRAM-1c, PROGRAM-1d, PROGRAM-1e, PROGRAM-1f, PROGRAM-1g, PROGRAM-1h.