The first step in developing strategy is analysis. You need to carry out an analysis of the organisation and the environment that it is operating in to be able to make informed decisions. There are 5 main areas that you need to analyse before starting to write your security strategy. You need a good understanding of:
Some of the information will need to be gathered through consultation with stakeholders (see Understanding the organisation); such as the board, the senior executives, partners and staff. Good consultation at this stage can help to encourage buy-in once the strategy is drafted (see Obtaining board approval). This toolkit provides guidance on each stage and also suggests a range of tools that can help you to do this.