2.2. Information Security Strategy
💡 First Principle: A strategy is only real if it says what the organization will not do this year — a document that tries to address every possible risk with no prioritization is a wish list, not a strategy.
Without a genuine strategy, security spending drifts toward whatever vendor pitch or recent headline was most persuasive, rather than the risks that actually matter to the business. A real strategy forces trade-offs: given finite budget and finite attention, which risks get addressed first, which get accepted for now, and which capabilities get built this year versus deferred. That prioritization work — not the framework poster on the wall — is what strategy actually is.
⚠️ Common Misconception: A security strategy is often confused with a security policy. Strategy sets long-term direction and business alignment (where are we going, and why); policy operationalizes that strategy into enforceable, near-term rules (what must everyone do). A security leader can have a detailed policy library and still have no real strategy behind it.