maintained and updated annually. Long-term goals and visions for the future are
discussed in a strategic plan. A strategic plan should include a risk assessment.
Tactical plan: The tactical plan is a midterm plan developed to provide more details on
accomplishing the goals set forth in the strategic plan. A tactical plan is typically useful
for about a year and often prescribes and schedules the tasks necessary to accomplish
organizational goals.
Operational plan: An operational plan is a short-term, highly detailed plan based on the
strategic and tactical plans. It is valid or useful only for a short time. Operational plans
must be updated often (such as monthly or quarterly) to retain compliance with tactical
plans. Operational plans spell out how to accomplish the various goals of the
organization. Operational plans include details on how the implementation processes
are in compliance with the organization’s security policy.
Security is a continuous process. Thus, the activity of security manag ement planning may have
a definitive initiation point. Effective security plans focus attention on specific and achievable
objectives, anticipate change and potential problems, and serve as a basis for decision making
for the entire organization. (Stewart et al., 2004)
4. Security Governance
Security governance is the collection of practices related to supporting, defining, and directing
the security efforts of an organization. Security governance is closely related to and often
intertwined with corporate and IT governance. The goals of these three governance agendas
are often the same or interrelated – Transceiver.
Some aspects of governance are imposed on organizations due to
legislative and regulatory compliance needs, while others are imposed by
industry guidelines or license requirements. All forms of governance,
including security governance, must be assessed and verified from time to
time. Various requirements for auditing and validation may be present
due to government regulations or industry best practices. The
organization as a whole should be given the direction, guidance, and tools
to provide sufficient oversight and management to address threats and
risks with a focus on eliminating downtime and keeping potential loss or
damage to a minimum.
Ultimately, security governance is the implementation of a security solution and a management
method that are tightly interconnected. Security governance directly oversees and gets
involved in all levels of security. Security is not and should not be treated as an IT issue only.
Instead, security affects every aspect of an organization. It is no longer, just something the IT
staff can handle on their own.
Lebanese National Security Policy Guidelines v1.7
Page
12 |