Tom Doyle
Security strategic planning, policy, and leadership
Mapped to the five official sections. All resources below are free, intermediate-to-advanced level, and skip entry-level material.
Section 1: Strategic Planning Foundations
Business Context Analysis & Strategic Security Planning Frameworks
- NIST Cybersecurity Framework 2.0 (NIST.CSWP.29) — The current official CSF 2.0 text: Govern, Identify, Protect, Detect, Respond, Recover functions used as the backbone of a strategic security program aligned to business objectives.
- NIST CSF 2.0 Resource & Overview Guide (SP 1299) — A companion guide explaining how to apply CSF 2.0 profiles and tiers when building an organization-specific strategic plan.
- NIST CSF 2.0 Enterprise Risk Management Quick-Start Guide (SP 1303) — Shows how to connect cybersecurity risk to enterprise risk management, directly relevant to translating security posture into business context.
Asset Analysis & Crown Jewels Analysis
- MITRE Crown Jewels Analysis (CJA) overview — MITRE's own description of the CJA methodology for identifying the cyber assets most critical to an organization's mission.
- MITRE: Crown Jewels Analysis for Industrial Control Systems (PDF) — A detailed, publicly released walkthrough of the CJA process, mission decomposition, and criticality scoring — applicable well beyond ICS.
- Cyber Resiliency and Criticality Analysis: CJA Under the Hood (MITRE, PDF) — Goes deeper into the mechanics of dependency mapping and mission-impact scoring behind crown jewels analysis.
Stakeholder Identification & Engagement
- A Guide to Stakeholder Analysis for Cybersecurity Researchers (arXiv, 2025) — A modern, free academic treatment of stakeholder-mapping methods (power/interest grids, salience models) applied specifically to security contexts.
- A Stakeholder Approach to Strategic Management (Freeman, academia.edu PDF) — The original Freeman stakeholder-theory chapter that underlies most modern stakeholder-engagement frameworks used in security leadership training.
30-60-90 Day Planning
Section 2: Strategic Roadmap Development
Security Vision, Framework Implementation & Gap Analysis
- CIS Critical Security Controls v8.1 — Free, prioritized control framework (18 controls, 3 Implementation Groups) commonly used as the target-state framework in a roadmap/gap-analysis exercise.
- CIS Controls Self-Assessment Tool (CIS CSAT) — Free web tool for scoring current-state maturity against CIS Controls, generating the gap data a roadmap is built from.
- NIST SP 800-53A Rev. 5: Assessing Security and Privacy Controls — Free assessment procedures used to determine current-state control effectiveness before building a target-state roadmap.
Business Case Development & Security Metrics
- Open FAIR Risk Analysis materials (FAIR Institute) — Free introductory chapter and model summary for Factor Analysis of Information Risk, the leading approach for quantifying risk in dollar terms for business cases.
- CISA: The Business Case for Security (PDF) — A free government-produced framework for building an ROI-based justification for security investment.
Board & Executive Presentation Methodologies
- Director's Handbook on Cyber-Risk Oversight, 5th ed. (NACD / Internet Security Alliance, PDF) — A free, board-oriented handbook of six oversight principles and boardroom tools — written from the perspective of the audience security leaders must brief.
- NACD/ISA: AI in Cybersecurity Handbook (PDF) — Free companion handbook on framing AI-related cyber risk for a board audience.
Section 3: Security Policy Development and Assessment
Policy Governance Frameworks & Lifecycle
- NIST SP 800-12 Rev. 1: An Introduction to Information Security (PDF) — Free NIST handbook covering policy types, governance structures, and how policy relates to the broader control lifecycle.
- SANS Information Security Policy Templates — A free library of dozens of ready-to-adapt policy templates (acceptable use, vulnerability management, incident response, etc.) with structure and language you can study directly.
Requirements Definition & Policy Assessment
- NIST SP 800-53A Rev. 5: Assessing Security and Privacy Controls (PDF/OSCAL) — Free, formal methodology for turning policy/control requirements into testable assessment procedures — directly applicable to the course's "policy assessment techniques" topic.
- CIS Controls v8.1 Implementation Groups Guide — Free guide to scoping policy/control requirements by organizational size and risk exposure (IG1–IG3).
Emerging Technology Considerations (Cloud & AI Policy)
- NIST AI Risk Management Framework 1.0 (NIST.AI.100-1, PDF) — Free federal framework (Govern/Map/Measure/Manage) for writing AI governance and usage policy — directly maps to the course's AI security policy lab.
- NIST Generative AI Profile (NIST.AI.600-1, PDF) — Free supplementary profile addressing generative-AI-specific risks for policy drafting.
- Cloud Security Alliance: Cloud Controls Matrix v4 — Free, free-to-download meta-framework of cloud-specific controls (17 domains) mapped to ISO 27001, NIST 800-53, and PCI DSS — the standard reference for writing cloud computing policy.
Section 4: Leadership and Management Competencies
Leadership Foundations & Situational Leadership
- ADP 6-22: Army Leadership and the Profession (PDF) — Free, public-release U.S. Army doctrine covering leadership principles, competencies, and the leader-development model — an unusually rigorous, real-world alternative to commercial leadership texts.
- OpenStax: Principles of Management (free textbook) — Peer-reviewed, fully free open textbook with dedicated chapters on leadership, motivation, teams, and organizational change — a legitimate MBA-level substitute for the course's leadership modules.
- Situational Leadership Model — Hersey & Blanchard overview (Toolshero) — Free explainer of the four leadership styles matched to follower readiness levels, the foundational model behind the course's situational leadership content.
Communication Techniques
- Business Communication for Success (open textbook, PDF) — Full free textbook on written and verbal business communication, including persuasive and executive communication chapters.
- Business Communication: Five Core Competencies (Open Textbook Library) — Free textbook built around professional, clear, concise, evidence-driven, and persuasive communication — directly useful for exec-facing communication skills.
Team Building
- Google re:Work: Understand Team Effectiveness (Project Aristotle) — Free, publicly released research and discussion guide from Google's multi-year study identifying psychological safety, dependability, structure, meaning, and impact as the five drivers of high-performing teams.
Change Management
- Kotter's 8-Step Change Model — original framework summary (Kotter Inc./secondary overview) — Free breakdown of Kotter's eight-step model (urgency, coalition, vision, communication, removing barriers, short-term wins, consolidation, anchoring change) — the standard model referenced in security change-management training.
- ADP 6-22: Army Leadership and the Profession (PDF) — Also includes a chapter on leading change and organizational transitions, reinforcing the change-management competency from a leadership-doctrine perspective.
Section 5: Strategic Planning Workshop (Capstone)
Business Case Studies (Harvard Business School Alternative)
- MIT Sloan LearningEdge — Free case studies and simulations from MIT Sloan covering strategy, leadership, and organizational change — a genuinely free substitute for the paid Harvard Business School case studies used in the SANS capstone.
- Ivey Publishing: Free Cases — Selected free cases from Ivey Business School (the world's second-largest case publisher after HBS) usable for the same style of case-based strategic analysis.
- The Case Centre: Free Case Collection — A rotating collection of free, full cases (including some from Stanford GSB and Copenhagen Business School) suitable for practicing the same case-analysis skills as the SANS Harvard case studies.
Executive Presentation & Board Communication
- Director's Handbook on Cyber-Risk Oversight, 5th ed. (NACD/ISA, PDF) — Reused here as the capstone reference for structuring an executive/board-level cybersecurity presentation, since it is written explicitly from the board's point of view.
Strategic Planning Methodology & Business Priority Alignment
- NIST CSF 2.0 (NIST.CSWP.29) — Reused as the capstone planning framework for synthesizing current-state assessment, target profile, and prioritized action plan — mirroring the course's final workshop deliverable.
- CISA: The Business Case for Security (PDF) — Useful as a final checklist for aligning a strategic plan to business priorities before an executive presentation.