6 ◾ Information Security Fundamentals
external customers, a documented concept of operations is necessary to address
activities such as penetration testing, weakness remediation, contingency planning
and testing, and annual controls testing. An operating plan for the function defines
the goals and objectives to be achieved over a relatively long period of time, nor-
mally 3 to 5 years. It provides milestones to be achieved and establishes priorities
and sequences for tasks that the organization must perform. Development of the
operating plan must be consistent with the overall agency strategic plan and IT
strategic plan.
In the following paragraphs, critical components of an organization-wide infor-
mation security function are described.