Skip to content
Digital Sentinel
All study guides
GIAC Strategic Planning, Policy, and LeadershipProfessional8 weeks

GIAC GSTRT — Strategic Planning, Policy and Leadership

The cert that made me a better engineer, not just a better manager. What GSTRT tests, how to build the index that passes it, and why the "soft" cert is the hard one.

6 min read

Let me guess what you're thinking. It's the "soft" cert. The one without packet captures or memory dumps.

I thought that too. I was wrong!

This is the exam that asks the question every technical person eventually runs into: you know exactly what needs fixing — so why won't anyone fund it? Answering that turns out to be a skill, and it's the one this cert teaches.

The exam at a glance

CertificationGIAC Strategic Planning, Policy, and Leadership
Associated courseSANS MGT514
FormatProctored, open book — printed materials only
Typical shapeAround 75 questions, roughly 2 hours, pass near 68%
Practice testsTwo included — use both

Open book, same as GCIH. Which means the same rule applies:

The index is the exam. If you've read my GCIH guide, you already know the drill — build the spreadsheet, write your own one-line definitions, print it, bind it, practise with it.

One difference worth knowing. GCIH lookups are things like "what port is that" — facts. GSTRT lookups are more often "which model is this" — concepts. So make your index heavier on model names, framework names and their one-line purpose, and lighter on raw data.

The three pillars

1. Strategic planning

This is the part that surprised me most.

Security strategy isn't a list of tools you want to buy. It's a story about where the business is going and what has to be true for it to get there safely.

What to know:

  • Mission, vision, values — and why a security strategy that ignores them gets rejected no matter how technically correct it is.
  • Environmental scanning — SWOT, PEST, competitive analysis. Boring names, genuinely useful once you've done one for real.
  • Current state → future state → gap. The whole roadmap is that sentence. Maturity models exist to make the "current state" part honest.
  • The business case. Cost, benefit, risk reduction, and the alternatives you considered. Executives fund options, not demands.
  • Metrics. The difference between a metric that proves you're busy and one that proves you're effective. Guess which one gets you budget.

2. Policy

Here's the thing nobody tells you: most security policy fails not because it's wrong, but because nobody reads it.

Know these cold, because the exam tests the distinction directly:

DocumentWhat it is
PolicyWhat we do and why. Mandatory. Rarely changes.
StandardThe specific requirement. Mandatory. Changes with tech.
ProcedureThe step-by-step. How you actually do it.
GuidelineRecommended, not mandatory. Advice.

Then the lifecycle: draft, review, approve, communicate, enforce, revise. Communicate and enforce are where real programmes fall over — a policy nobody was told about and nobody is measured against isn't a control, it's a document.

And write for the reader. Short. Plain. Specific about who does what. If someone needs a security background to understand your acceptable use policy, it will not change anyone's behaviour.

3. Leadership

The part I expected to find fluffy, and didn't.

  • Management vs leadership. Management is planning, organising, controlling. Leadership is influence and direction. You need both and they are not the same skill.
  • Motivation — what actually moves people, and why "we'll get breached otherwise" stops working after the second time you say it.
  • Building and keeping a team — hiring, developing, and the reasons good analysts leave.
  • Communication up and down. Same finding, three audiences: engineers, managers, the board. Three completely different versions.
  • Influence without authority. Most security work depends on people who don't report to you doing something they didn't plan to do. This is the whole job.
  • Change management — why people resist, and what to do about it.

How I studied for it

Weeks 1–4: read it properly, no index yet. Just understanding. And for every model, I wrote one sentence about where I'd seen it fail in real life. That sentence is what made them stick.

Weeks 5–7: build the index. Second pass, spreadsheet open. Term, page, my own definition. Heavier on models and frameworks than on facts.

Week 8: both practice tests. First one with the index only. Fix every gap it exposes, reprint, then sit the second. If test two is comfortably over the pass mark with time left, you're ready.

I love hand-to-paper for this one. Flowcharts for the policy lifecycle, current-state-to-future-state drawn out by hand. Something about drawing it makes it stay.

What did we learn?

  1. The "soft" cert is not the easy cert — it's just hard in a different direction.
  2. Strategy is a story about the business, not a shopping list of tools.
  3. Policy, standard, procedure, guideline. Know the difference, it's tested directly.
  4. Communicating and enforcing policy matters more than writing it.
  5. Influence without authority is most of security leadership.
  6. Your index should be heavy on models and frameworks, not raw facts.

Would I recommend it?

Yes — and especially if you're technical and slightly suspicious of it. That was me.

The engineers who get their projects funded aren't always the best engineers. They're the ones who can explain risk in the language the person holding the budget already speaks. This cert is a structured way to learn that language.

Studying for this one too? What's your target date? I'd genuinely like to know what's working for you.

Keep going!

Resources

  • GIAC GSTRT — the official page, and the only source for current exam details
  • SANS MGT514 — the associated course, if your employer will fund it
  • The two included practice tests — the best readiness signal you'll get
  • My GCIH guide — the index-building method in full, it applies here too
TagsGIACGSTRTleadershipstrategycertification