An information security strategic plan can position an organization to mitigate, transfer, accept or avoid information risk related to people, processes and technologies. An established strategy also helps the organization adequately protect the confidentiality, integrity and availability of information. The plan should contain a list of deliverables or benchmarks for the initiatives, including the name of the person responsible for each. The better alignment and integration between business and IT strategies, the better it is to meet expectations and get the right things done in a prioritized order.”]
Source: https://securityintelligence.com/the-importance-of-building-an-information-security-strategic-plan/