The term “operational strategies” is a misnomer. It is an incorrect attempt to define how an organization executes its overarching strategic goals through day-to-day actions.
ComplianceForge wrote an excellent guide contrasting strategy, operations and tactics, emphasizing that:
For cybersecurity, operations include designing incident response workflows, defining risk assessment cadences, selecting tooling, staffing functions and integrating maturity models. They ensure strategy isn't a theoretical statement but a runnable program.