Quality, Expert-Derived Cybersecurity Documentation To Keep Organizations Secure, Compliant & Resilient  |  Got Questions? +1-307-241-8740
ComplianceForge

Operationalizing Cybersecurity Planning Model (OCPM)

The ComplianceForge Operationalizing Cybersecurity Planning Model™ (OCPM) takes a practical view towards implementing cybersecurity business plans. CISOs are often not at a loss for a plan, but executing these plans often fall short due to disconnects between strategic, operational and tactical components in the planning and implementing processes. Where the rubber meets the road, Individual Contributors (ICs) need to know (1) how they fit into business planning, (2) what their priorities are and (3) what is expected from them in their duties. When looking at it from an auditability perspective, the evidence of due diligence and due care should match what the cybersecurity business plan is attempting to achieve.

The central focus of any cybersecurity business plan should be a Capability Maturity Model (CMM) target that provides quantifiable expectations for People, Processes and Technologies (PPT), since this helps prevent a “moving target” by establishing an attainable expectation for “what right looks like” in terms of PPT. Generally, cybersecurity business plans take a phased, multi-year approach to meet these CMM-based cybersecurity objectives. Those objectives, in conjunction with the business plan, demonstrate evidence of due diligence on behalf of the CISO and his/her leadership team. The objectives prioritize the organization’s service catalog through influencing procedures at the IC-level for how PPT are implemented at the tactical level. Those Standardized Operating Procedures (SOPs)not only direct the workflow of ICs, but the output from procedures provide evidence of due care.

ComplianceForge has simplified the concept of operationalizing cybersecurity planning in in the following downloadable diagram to demonstrate the unique nature of these components, as well as the dependencies that exist:

CP-CMM ComplianceForge CSOP Operationalizing Cybersecurity Planning Model
Common Questions

Frequently-Asked Questions

Here are answers to common questions about operationalizing cybersecurity planning:

What is the Operationalizing Cybersecurity Planning Model (OCPM)?
The Operationalizing Cybersecurity Planning Model (OCPM) is a free ComplianceForge diagram that shows how a cybersecurity business plan flows down into daily work. It links strategic objectives to operational priorities in the service catalog and to tactical Standardized Operating Procedures (SOPs) that individual contributors follow. The goal is that each contributor knows how they fit into business planning, what their priorities are, and what is expected of them.
Why do cybersecurity plans fail during execution?
Cybersecurity plans often fall short during execution because of disconnects between their strategic, operational and tactical components, not because a plan is missing. CISOs are often not at a loss for a plan. Problems arise when individual contributors are unclear about how they fit into business planning, what their priorities are, and what is expected of them, so their daily work doesn't clearly support the plan's objectives.
How does a capability maturity model target support cybersecurity planning?
A Capability Maturity Model (CMM) target gives a cybersecurity business plan quantifiable expectations for people, processes and technologies. Making the CMM target the central focus of your plan prevents a moving target and defines an attainable picture of what right looks like. Your team can then measure the gap between current and target maturity and justify the resources needed to close it.
How do procedures provide evidence of due care?
Procedures provide evidence of due care because their output shows that controls are actually performed day to day. In the OCPM, Standardized Operating Procedures (SOPs) direct the workflow of individual contributors, and the records they produce, such as tickets, logs and review sign-offs, become that evidence. Evidence of due diligence and due care should also match what your cybersecurity business plan is trying to achieve.
What documents are needed to operationalize a cybersecurity business plan?
In the OCPM, you need a cybersecurity business plan with CMM targets and documented procedures that tie daily work to those targets. ComplianceForge's Cybersecurity Business Plan (CBP) is an editable Word template covering vision, mission, strategy, CMM target definitions and a strategic roadmap. Our Cybersecurity Standardized Operating Procedures (CSOP) give you editable procedure templates that pair with matching policies and standards, so tactical work traces back to the plan.