This chapter provides the framework for creating an overarching corporate Information Technology (IT) security project plan. In subsequent chapters, we'll step through Individual Security Area Projects (ISAPs). This and subsequent chapters are intended to be used as templates to guide you through your security project planning process.There is no one-size-fits-all approach to any security project planning process; thus, you will need to modify your security project plan to fit your organization's requirements. This chapter provides the basic building blocks to help you get started. As you read this chapter, keep in mind that the same principles apply, with some variation, to each of the ISAPs discussed later in this book. As you become familiar with the framework used in this chapter, you'll be able to see more clearly how this and subsequent ISAP plans should be modified to fit your own unique needs. This chapter also discusses a security audit.

