Policy
What is Policy?
A formal statement of management intent and direction. Security policies establish the rules, expectations, and standards that guide an organisation's approach to information security.
Terms that appear alongside policy
Each of these is named in at least one of the same controls as policy. The number is how many controls name both.
- governance 96 shared controls
- compliance 95 shared controls
- audit 79 shared controls
- information security 74 shared controls
- nist 72 shared controls
- cybersecurity 60 shared controls
- privacy policy 44 shared controls
- access control 43 shared controls
Frameworks that govern policy
What the standards actually require on policy
Requirements naming policy across 6 standards, quoted from the control text.
Keep approved logging and monitoring policies and procedures, and review them at least annually.
CCM-LOG-01 · Logging and Monitoring Policy and Procedures →Software-enforced Separation and Policy Enforcement. Implement software-enforced separation and policy enforcement mechanisms between [organization-defined]
NIST800-SC-50 · Software-enforced Separation and Policy Enforcement. Implement software-enforced separation and policy enforcement mechanisms between [organization-defined] →Extends media protection policy to media moving to and from suppliers and integrators.
161R1-MP-1 · Policy and Procedures →Deploy Policy Enforcement Points in front of every protected resource, whether at the application, gateway, micro service, or network layer. Coverage gaps undermine the entire architecture.
SP800-207-3.3 · Policy Enforcement Point Coverage →Information must be classified according to the harm that could result from its compromise, with markings applied consistently and only by authorised originators.
PSPF-2024-POL-5 · Policy 5: Classification system →Maintain and issue encryption and key management policies that mandate state-of-the-art algorithms and network protocols, tie encryption strength to the information classification scheme, cover the full key lifecycle, and reflect applicable legal obligations.
C5-CRY-01 · Policy for the use of encryption procedures and key management →Questions people ask about policy
What is Policy?
Why is Policy important for compliance?
Which compliance frameworks address Policy?
Where can I learn more about Policy?
See how Policy applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.