Deciding the overall approach.
WHAT A STRATEGY COVERS
What will be tested, and to what depth What will not be How risk is assessed What is automated and what is not What environments and data are used Who does what What conditions must be met to release
WHAT IT IS NOT
A list of test cases.
WHAT MAKES IT USEFUL
Being specific enough to guide decisions.
WHAT MAKES ONE USELESS
Generic statements applying to any project.
WHAT TO BASE IT ON
The actual risks of this system.
WHAT TO STATE EXPLICITLY
What is out of scope, and why.
WHY
It is the part that protects you afterwards.
WHAT TO AGREE WITH STAKEHOLDERS
The level of assurance they are paying for.
WHY THAT FRAMING
More testing costs more, and the appropriate amount is a business decision.
WHAT TO KEEP SHORT
The document.
WHY
A long strategy is not read, and therefore not followed.
WHAT TO REVISIT
The strategy, as the system and its risks change.
WHAT TO DISTRIBUTE
It, to everyone affected.