To begin defining an organizational security program, you need to first truly understand your organization. You need to evaluate if there is a proper governance program in place. Then you need to understand the culture of the organization to include job functions, industry, and business drivers. This may include performing a comprehensive assessment of the organization. Ideally, you should collect information from similar organizations to see how you compare.