Taking a strategic approach to planning and implementation is required in order to achieve a successful information security program. Since the enactment of FISMA in 2002, most Federal agencies have taken a tactical approach to measuring progress against a scorecard.