Start by selecting an established cybersecurity framework and mapping current controls against it. That gives the team a common baseline, exposes control gaps, and creates a roadmap for prioritising work. The framework should guide decisions, not become paperwork. From there, define milestones, track progress against the baseline, and use the mapping to justify investment and sequencing.
Start with a framework, not a pile of controls
A new CISO with a blank slate should treat the first phase as baseline building, not programme invention. An established framework gives the organisation a shared language for what “good” looks like, which makes it easier to compare current-state controls, spot missing capabilities, and avoid arguing from anecdotes. For control selection and implementation guidance, ISO/IEC 27002:2022 Information Security Controls is a practical reference point.
The real value is sequencing. When you map what already exists to a recognised control structure, you can separate “not yet built” from “built but weak” and “built but undocumented”. That distinction matters because a first-phase programme should reduce uncertainty before it tries to reduce everything else.
How to turn the baseline into a roadmap
Once the framework is chosen, the next step is to map current controls against it at a level that is useful to executives and operators. The output should show coverage, gaps, ownership, and confidence level for each control area, so the CISO can prioritise work on the highest-risk gaps first. A broad control catalogue such as NIST SP 800-53 Rev 5 Security and Privacy Controls can help when the organisation needs a more detailed control inventory.
This phase should also define milestones that are small enough to track and large enough to matter. A good roadmap usually combines quick wins, foundational control uplift, and longer-term capability building, so the programme demonstrates progress without losing sight of structural issues. If the mapping is too coarse, it will not support investment decisions; if it is too granular, it becomes administration instead of management.
What the first phase is really trying to achieve
The first phase is not about proving that the organisation is “secure”. It is about establishing governance, prioritisation, and decision support. A framework-based baseline gives the CISO a defensible way to explain why one control area should be funded before another, why some work can wait, and which gaps create the largest exposure.
It also prevents the common failure mode where teams confuse activity with progress. A programme can generate policies, tools, and committee meetings very quickly, but without a mapped baseline there is no reliable way to show whether risk is actually decreasing. The framework becomes the operating model for choices, not just a document for audit season.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM-01 — Risk Management Strategy | The question is about structuring early programme priorities and roadmap decisions. |
| Recommendation — Define a risk-based baseline and use it to prioritise the first programme milestones. | ||
| ISO/IEC 27001:2022 | A.5.1 — Policies for information security | A blank-slate programme needs governance scaffolding before control work can scale. |
| Recommendation — Establish the security programme baseline under an information security policy and governance model. | ||
| NIST SP 800-53 Rev 5 | PM-9 — Risk Management Strategy | The CISO is setting initial security programme direction and prioritisation. |
| Recommendation — Align the programme roadmap to an explicit risk management strategy. | ||
| CIS Controls v8 | CIS-18 — Penetration Testing | Early control mapping often feeds validation and measurement of implementation gaps. |
| Recommendation — Use control validation to confirm the baseline before scaling the programme. | ||
Practitioner Guidance
What to prioritise: Start with the control areas that materially affect visibility, access, and recovery, because those are usually the fastest way to reduce uncertainty across the rest of the programme. Then expand into deeper maturity work once the organisation can show where it stands and what changed.
What to verify: Confirm that every mapped control has an owner, a current status, and evidence that can be reviewed without interpretation. If a control cannot be evidenced, it is not ready to anchor investment decisions, even if it sounds complete on paper.
What good looks like: The CISO can point to a concise baseline, a ranked gap list, and a roadmap that ties each major initiative to a specific control improvement or risk reduction outcome.
Practitioner takeaway: The first phase should create decision quality, not just documentation quality, by turning the current-state security picture into a prioritised roadmap the business can actually fund and follow.