An organisation with an approved, well-aligned security strategy completes a major acquisition that adds a regulated line of business and shifts the corporate strategy towards a new market. The information security manager wants the security strategy to remain aligned as these changes take effect. Which practice best maintains strategic alignment over time?
- AFreeze the approved strategy for its full multi-year term to preserve stability and avoid disrupting committed initiatives
- BReview the strategy against the revised corporate objectives whenever the business direction changes materially, and realign initiatives accordingly Correct
- CDefer any change until the next scheduled three-year strategy refresh, then incorporate all accumulated business changes at once
- DDelegate alignment to each business unit so the units adapt the strategy locally to fit their own changing circumstances
Why A is wrong: Tempting because stability protects in-flight delivery, but freezing the strategy lets it drift from a changed business and defeats the purpose of keeping it aligned.
Why B is correct: Correct because maintaining alignment requires revisiting the strategy against business objectives when they change materially, so the security strategy tracks the organisation rather than lagging it.
Why C is wrong: Tempting because a single periodic refresh is efficient, yet waiting years to absorb a market shift leaves the strategy misaligned through the very period the change matters most.
Why D is wrong: Tempting because local adaptation seems responsive, but devolving alignment fragments the enterprise strategy and removes the manager's accountability for coherent governance.