What items need to be considered when developing an information security strategy for an organization? How can the organization’s security structure vary depending on the grass roots (bottom-up) or senior management (top-down) approach being implemented? Discuss why your approach to security structure helps shape policy.

Citations and references required 


