The first step is to research legal and regulatory requirements for the new locations. Different countries have varying security and privacy laws, and understanding these is critical before adapting policies or procedures. "Security requirements will vary depending on local legal and regulatory obligations, which must be understood as part of international expansion." - CISM Review Manual 15th Edition, Chapter 1: Information Security Governance, Section: Compliance Requirements The ISACA CISM practice database also highlights this step as the initial and critical move in international expansions.