BCC Enterprise Information Security Program by creating the BCC Enterprise Security Strategic Plan
Part 1
Write a 5- to 6-page BCC Enterprise Information Security Strategic Plan that includes the following:
• Information security vision, mission, and objectives
• Balanced scorecard for each domain
• Control framework and major security areas to be assessed (COBIT or ISO 27002)
• SWOT analysis of the internal and external assessment identifying at least three security initiatives that improve the security objectives
• Operational action plan to complete the security initiatives
Part 2
Create a 6- to 8-slide, media-rich Microsoft® PowerPoint® presentation in which you:
• Define at least three key performance indicators for the security objectives and initiatives.
• Align the key performance indicators to the security objectives and initiatives as specified in the BCC profile.
Sample Answer
Part 1: BCC Enterprise Information Security Strategic Plan
1. Information Security Vision, Mission, and Objectives
- Vision: Clearly state your desired future state for BCC’s information security posture. (e.g., “To be a leader in secure information management, protecting our critical assets and fostering a culture of cyber resilience.”)
- Mission: Define the purpose of the information security program. (e.g., “To safeguard BCC’s confidential information, ensure system availability and integrity, and comply with relevant security regulations.”)