One-page security strategy
One approvable page: five to seven security objectives, each tied to a business objective and a risk, with a measure, a baseline, a target and an owner role.
Governance5 Sept 20263 min read
On this page
one-page-security-strategy.xlsx · 11 kBLicensed CC BY 4.0
What this is
The page a board or executive committee approves as the security strategy. One sheet holds five to seven security objectives, each tied to a business objective and to a risk, with a measure, a baseline, a target and an owner role. Three supporting sheets hold the work closing the gap, the dated obligations the plan must clear, and the approvals across the horizon. It is the artefact produced by section 3.8 of Security strategy on one page.
How to use it
- Delete the example rows. Every one is invented and prefixed EXAMPLE - delete.
- Fill the business objective column first, in the organisation's own words, at clause 4.1, "Understanding the organization and its context" 1. See section 3.1.
- Take the risk identifiers from the rows beyond appetite. The analysis stays in the risk register; this sheet carries the reference.
- Write each objective as an end condition, not a project. Clause 6.2 is "Information security objectives and planning to achieve them" 2. See section 3.3.
- Measure the baseline before the page is tabled, under clause 9.1, "Monitoring, measurement, analysis and evaluation" 3.
- Name an owner role that controls the resource, under clause 5.3, "Organizational roles, responsibilities and authorities" 4.
- Put every dated obligation on the Constraints sheet, never in an objective. Name what must be true by the date, and check an initiative reaches it. See section 3.6.
- Record the approval and each review in the Review log. Clause 9.3 is "Management review", with 9.3.2 inputs and 9.3.3 results 5. See section 3.9.
What good looks like
Six of the ten columns, from two of the rows shipped in the workbook.
| ID | Security objective (end condition) | Measure | Baseline | Target | Owner (role) |
|---|---|---|---|---|---|
| O-001 | Every production system authenticates through the central identity service | Production systems on central identity | 62 per cent | 100 per cent | Head of platform engineering |
| O-003 | Every AI system in production is registered and has trained operators | Registered systems with an owner and trained operators | 0 of 4 | 4 of 4 | Head of data and AI |
Fields
| Field | Required | Meaning | Common mistake |
|---|---|---|---|
| Business objective | yes | What the organisation is trying to do, in its words | A security ambition restated as a business one |
| Security objective | yes | The end condition, not the project reaching it | A roadmap item with a delivery date attached |
| Risk it moves (ID) | yes | The register rows the objective exists to move | A theme with no identifier behind it |
| Measure, baseline, target | yes | The quantity, its value now, and the committed value | A target set with no baseline measured |
| Target date | yes | When the target is committed to be reached | A regulatory date reused as the target date |
| Owner (role) | yes | The role accountable, never a person | The security function owning what it cannot deliver |
| Initiatives (IDs) | yes | The work closing the gap, tied to this objective | Initiatives kept without an objective |
| Obligation, date (Constraints) | yes where dated | What must be true, and by when | A constraint written into the objective column |
Download
- File:
one-page-security-strategy.xlsx(xlsx, 11 KB) — sheets Read first, Strategy, Initiatives, Constraints, Review log. - Markdown variant: the same tables in plain markdown, at
content/templates/assets/_one-page-security-strategy.md. - Licence: CC BY 4.0 — reuse and adapt with attribution to GRCIDE.
- Version: 1.0, 2026-09-05. No personal data, no organisation names, no macros.
Related
- Playbook: Security strategy on one page
- Playbook: Board and management reporting for security
- Template: One-page risk picture, which this page reads from
References
- ISO/IEC. Information security management systems — Requirements. ISO/IEC 27001:2022. Clause titles read at https://www.iso.org/obp/ui/#iso:std:iso-iec:27001:ed-3:v1:en 6
- National Institute of Standards and Technology. The NIST Cybersecurity Framework (CSF) 2.0. NIST CSWP 29. https://doi.org/10.6028/NIST.CSWP.29 7
Standards and certification names are the property of their respective owners. GRCIDE is an independent publication and is not affiliated with, authorized, sponsored or endorsed by ISO, IEC, NIST or any other standards body.
Sources
- 1ISO/IEC 27001:2022 clause 4.1, iso.org/obp · verified 2026-09-03
- 2ISO/IEC 27001:2022 clause 6.2, iso.org/obp · verified 2026-09-03
- 3ISO/IEC 27001:2022 clause 9.1, iso.org/obp · verified 2026-09-03
- 4ISO/IEC 27001:2022 clause 5.3, iso.org/obp · verified 2026-09-03
- 5ISO/IEC 27001:2022 clause 9.3, iso.org/obp · verified 2026-09-03
- 6ISO/IEC 27001:2022 contents, iso.org/obp · verified 2026-09-03
- 7NIST CSWP 29 Sec. 3.1, nvlpubs.nist.gov · verified 2026-09-05