National Cyber Strategies and the Framework Hierarchy

▶ Watch (2:31)

About 75% of countries have national cyber strategies, coordinated by the ITU, a United Nations agency founded in 1865 to standardize telecommunications. Those strategies cascade into national security frameworks. Brätsch then mapped the leading security frameworks against leading PM frameworks: PMBOK, SAFe, Scrum, PRINCE2. Both sides share vocabulary: processes, methodologies, knowledge areas. But the alignment is one-directional. PM frameworks dominate company culture; security requirements have to work through them.

How PM Frameworks Rank on Security Support

▶ Watch (10:00)

Brätsch ranked PM frameworks on security readiness across three tiers: no support, supportive, and support. OKRs are not relevant for security at all. PM² and Critical Chain are too methodology-specific to generalize. Agile and PMBOK fall into the supportive tier. The Scrum guide does not mention security, but agile’s iterative structure creates natural checkpoints for security review. Only four frameworks are genuinely relevant for security work today. The rest need substantial customization before they handle compliance requirements.

PMI and SAFe: Reaching the Top Tier

▶ Watch (14:16)

PMI’s main guides from 2021 total nearly 1,000 pages and mention “information security” exactly once. Security is classified as an environmental factor. But in 2021 PMI also acquired Disciplined Agile, a separate framework that treats security as a process blade embedded into mindset and workflows. SAFe earns the same top rating by a different path. It adopted SecOps and shift-left security champions, and its software factory concept lets teams swap compliance frameworks per customer without disrupting the core product.

Why Security Requirements Break Standard PM Workflows

▶ Watch (23:33)

Security requirements don’t behave like product features. Writing them cleanly requires input from compliance, legal, and business teams, not just the development team. Dumping them into a sprint backlog misses the cross-organizational complexity they carry. Brätsch’s conclusion after reviewing four leading PM frameworks: none answers how to estimate or prioritize security requirements against product features. The gap is structural. Introducing a security team does not integrate security. A framework that describes what to do but not how to value it gives teams nowhere to start.

ROSI: The Missing Business Logic for Security Prioritization

▶ Watch (26:14)

ROSI (Return on Security Investment) has existed since 2012 as a quantitative risk method. CFOs use it for multi-year investment decisions. Brätsch’s example: a DDoS attack costs $1M. With a 0.4 probability, the annual expected loss is $400K. Add a DDoS mitigation solution, reduce that probability, subtract the implementation cost. Return: $880K. The numbers come from industry data, not guesswork. An estimate grounded in observable rates gives security a financial argument that product owners and project managers can compare directly against feature costs.

Involve Security Before Project Scope Is Set

▶ Watch (31:35)

The fix is sequence. Establish a business vision for security first. That means ROSI or a comparable quantification method. Then build the workflow, then add the methodologies the PM framework provides. Most importantly: bring security into the sales process, before requirements are written. Brätsch’s observation: many companies involve security teams only after project scope is defined. By then, direction is set and corrections are expensive. Getting security consultants into early customer conversations changes what questions get asked before a line of code is written.

Notable Quotes

for security there is no business Vision Stefan Brätsch · ▶ Watch (25:36)

main books so nearly a thousand Pages we would find the word security 17 Stefan Brätsch · ▶ Watch (15:19)

Key Takeaways

  • Only four PM frameworks address security meaningfully; most need heavy customization before they handle compliance requirements.
  • PMI’s PMBOK mentions “information security” once in 1,000 pages; its 2021 Disciplined Agile acquisition fills that gap.
  • ROSI converts threat probability and mitigation cost into a financial estimate product owners can act on.
  • Involve security consultants before project scope is defined; correcting direction mid-project costs far more than starting right.

About the Speaker(s)

Stefan Brätsch is an IT management consultant and CISO with over twenty years of experience as a computer scientist. He specializes in project management, coaching, digital transformation, and business analysis for software products. Operating as a freelancer across Germany and Europe, he supports companies on their security and digital transformation missions.