Back to templates
    Template

    One-page security strategy

    One approvable page: five to seven security objectives, each tied to a business objective and a risk, with a measure, a baseline, a target and an owner role.

    Governance5 Sept 20263 min read

    ISO/IEC 27001:2022NIST CSWP 29
    On this page
    Download the template

    one-page-security-strategy.xlsx · 11 kBLicensed CC BY 4.0

    What this is

    The page a board or executive committee approves as the security strategy. One sheet holds five to seven security objectives, each tied to a business objective and to a risk, with a measure, a baseline, a target and an owner role. Three supporting sheets hold the work closing the gap, the dated obligations the plan must clear, and the approvals across the horizon. It is the artefact produced by section 3.8 of Security strategy on one page.

    How to use it

    1. Delete the example rows. Every one is invented and prefixed EXAMPLE - delete.
    2. Fill the business objective column first, in the organisation's own words, at clause 4.1, "Understanding the organization and its context" 1. See section 3.1.
    3. Take the risk identifiers from the rows beyond appetite. The analysis stays in the risk register; this sheet carries the reference.
    4. Write each objective as an end condition, not a project. Clause 6.2 is "Information security objectives and planning to achieve them" 2. See section 3.3.
    5. Measure the baseline before the page is tabled, under clause 9.1, "Monitoring, measurement, analysis and evaluation" 3.
    6. Name an owner role that controls the resource, under clause 5.3, "Organizational roles, responsibilities and authorities" 4.
    7. Put every dated obligation on the Constraints sheet, never in an objective. Name what must be true by the date, and check an initiative reaches it. See section 3.6.
    8. Record the approval and each review in the Review log. Clause 9.3 is "Management review", with 9.3.2 inputs and 9.3.3 results 5. See section 3.9.

    What good looks like

    Six of the ten columns, from two of the rows shipped in the workbook.

    IDSecurity objective (end condition)MeasureBaselineTargetOwner (role)
    O-001Every production system authenticates through the central identity serviceProduction systems on central identity62 per cent100 per centHead of platform engineering
    O-003Every AI system in production is registered and has trained operatorsRegistered systems with an owner and trained operators0 of 44 of 4Head of data and AI

    Fields

    FieldRequiredMeaningCommon mistake
    Business objectiveyesWhat the organisation is trying to do, in its wordsA security ambition restated as a business one
    Security objectiveyesThe end condition, not the project reaching itA roadmap item with a delivery date attached
    Risk it moves (ID)yesThe register rows the objective exists to moveA theme with no identifier behind it
    Measure, baseline, targetyesThe quantity, its value now, and the committed valueA target set with no baseline measured
    Target dateyesWhen the target is committed to be reachedA regulatory date reused as the target date
    Owner (role)yesThe role accountable, never a personThe security function owning what it cannot deliver
    Initiatives (IDs)yesThe work closing the gap, tied to this objectiveInitiatives kept without an objective
    Obligation, date (Constraints)yes where datedWhat must be true, and by whenA constraint written into the objective column

    Download

    • File: one-page-security-strategy.xlsx (xlsx, 11 KB) — sheets Read first, Strategy, Initiatives, Constraints, Review log.
    • Markdown variant: the same tables in plain markdown, at content/templates/assets/_one-page-security-strategy.md.
    • Licence: CC BY 4.0 — reuse and adapt with attribution to GRCIDE.
    • Version: 1.0, 2026-09-05. No personal data, no organisation names, no macros.

    References

    1. ISO/IEC. Information security management systems — Requirements. ISO/IEC 27001:2022. Clause titles read at https://www.iso.org/obp/ui/#iso:std:iso-iec:27001:ed-3:v1:en 6
    2. National Institute of Standards and Technology. The NIST Cybersecurity Framework (CSF) 2.0. NIST CSWP 29. https://doi.org/10.6028/NIST.CSWP.29 7

    Standards and certification names are the property of their respective owners. GRCIDE is an independent publication and is not affiliated with, authorized, sponsored or endorsed by ISO, IEC, NIST or any other standards body.

    Sources

    1. 1ISO/IEC 27001:2022 clause 4.1, iso.org/obp · verified 2026-09-03
    2. 2ISO/IEC 27001:2022 clause 6.2, iso.org/obp · verified 2026-09-03
    3. 3ISO/IEC 27001:2022 clause 9.1, iso.org/obp · verified 2026-09-03
    4. 4ISO/IEC 27001:2022 clause 5.3, iso.org/obp · verified 2026-09-03
    5. 5ISO/IEC 27001:2022 clause 9.3, iso.org/obp · verified 2026-09-03
    6. 6ISO/IEC 27001:2022 contents, iso.org/obp · verified 2026-09-03
    7. 7NIST CSWP 29 Sec. 3.1, nvlpubs.nist.gov · verified 2026-09-05