1. ISACA
CISM Review Manual
16th Edition. Domain 1: Information Security Governance. The manual describes the process of strategy development and implementation. It clarifies that a strategy is translated into a roadmap
which is then executed through specific projects. The development of project plans is the logical step to operationalize the high-level initiatives outlined in the roadmap. (Specifically
the concepts in Task G2: "Develop a strategy to implement the information security program" and its supporting content imply this hierarchical breakdown from strategy to roadmap to project-level execution).
2. Calder
A.
& Watkins
S. (2019). IT Governance: An International Guide to Data Security and ISO 27001/ISO 27002 (7th ed.). Kogan Page. Chapter 6
"Information Security Management System (ISMS)
" discusses the Plan-Do-Check-Act (PDCA) cycle. Creating a strategy and roadmap falls within the "Plan" phase. Developing detailed project plans is the transition from high-level planning to the "Do" phase
where the plans are executed.
3. University of Washington
Information Technology Courseware
"IT Strategy
Plans & Roadmaps." This resource distinguishes between strategies (the 'why')
roadmaps (the 'what' and 'when' at a high level)
and project plans (the detailed 'how'). It establishes that project plans are derived from the strategic roadmap to guide execution. This aligns with the principle that detailed planning follows high-level strategic outlining.