2.2.1. Strategy Development and Alignment with Business Goals
💡 First Principle: A strategy that isn't derived from a documented gap between current and desired risk posture is just a list of activities that feels productive without being prioritized.
Strategy development starts by comparing where the organization's risk posture actually is today against where it needs to be to support its business objectives — a gap analysis, not a brainstorm. If the business plans to expand into a new regulated market next year, that single business objective should visibly shape the security roadmap: new compliance obligations, new data residency requirements, new control investments, all tied back to that specific business driver rather than a generic "improve security" mandate.
| Current State | Desired State | Gap | Roadmap Priority |
|---|---|---|---|
| No formal vendor risk program | Tiered vendor risk assessments for all critical suppliers | No visibility into third-party exposure | High — precedes planned outsourcing initiative |
| Manual log review | Centralized SIEM with correlation rules | Slow detection, inconsistent coverage | Medium — funded next fiscal year |
| Annual security awareness training only | Continuous, role-based training with phishing simulation | Low behavior-change impact | Medium |
Executive sponsorship is what converts a gap analysis into a funded roadmap: without a senior sponsor who can defend the strategy's priorities against competing budget requests, even an excellent gap analysis remains a shelved document. This is also why strategy is never a one-time exercise — as business objectives, the threat landscape, and risk appetite shift, the gap being closed shifts with them, and a strategy set once at program launch and never revisited quietly drifts out of alignment with what the business actually needs.
⚠️ Exam Trap: Watch for scenarios describing a strategy that was written years ago and never revisited despite major business changes (a merger, a new product line, a new regulatory market). The correct answer recognizes stale strategy as a governance failure, not a neutral fact — strategy requires at least annual reassessment.
Reflection Question: Your organization acquired a company in a new regulated industry eight months ago, but the security strategy hasn't been updated since before the acquisition. What specific risks does this create, and whose responsibility is it to trigger a strategy refresh?