
Saby Waraich
CIO,
Clackamas Community College
Are you struggling to decide how to prioritize your scarce information security resources? How do you move from a reactive approach to security toward a proactive approach with strategic planning? A good strategy considers the full spectrum of information security, including people, processes, and technology. Security decisions should be made based on the security risks facing your organization, not just on “best practices." Your information security strategy should demonstrate the alignment between business goals and strategies. We will share our journey of building an information security strategy that helped us to get buy-in from our executive leadership and helped create an information security road map.