Skip to content

Policy

What is Policy?

A formal statement of management intent and direction. Security policies establish the rules, expectations, and standards that guide an organisation's approach to information security.

Information Security

Each of these is named in at least one of the same controls as policy. The number is how many controls name both.

What the standards actually require on policy

Requirements naming policy across 6 standards, quoted from the control text.

Keep approved logging and monitoring policies and procedures, and review them at least annually.

CCM-LOG-01 · Logging and Monitoring Policy and Procedures

Software-enforced Separation and Policy Enforcement. Implement software-enforced separation and policy enforcement mechanisms between [organization-defined]

NIST800-SC-50 · Software-enforced Separation and Policy Enforcement. Implement software-enforced separation and policy enforcement mechanisms between [organization-defined]

Extends media protection policy to media moving to and from suppliers and integrators.

161R1-MP-1 · Policy and Procedures
NIST SP 800-20719 controls

Deploy Policy Enforcement Points in front of every protected resource, whether at the application, gateway, micro service, or network layer. Coverage gaps undermine the entire architecture.

SP800-207-3.3 · Policy Enforcement Point Coverage

Information must be classified according to the harm that could result from its compromise, with markings applied consistently and only by authorised originators.

PSPF-2024-POL-5 · Policy 5: Classification system
C5 (Germany)12 controls

Maintain and issue encryption and key management policies that mandate state-of-the-art algorithms and network protocols, tie encryption strength to the information classification scheme, cover the full key lifecycle, and reflect applicable legal obligations.

C5-CRY-01 · Policy for the use of encryption procedures and key management

Questions people ask about policy

What is Policy?
A formal statement of management intent and direction. Security policies establish the rules, expectations, and standards that guide an organisation's approach to information security.
Why is Policy important for compliance?
Policy is a key concept in Information Security. Understanding policy helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Policy?
Policy appears in the requirement text of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, NIST SP 800-53 Rev 5, NIST SP 800-161 Rev 1, NIST SP 800-207, Protective Security Policy Framework (PSPF) Release 2024. Across these standards we have identified 132 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Policy?
Explore our compliance framework pages to see how policy applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Policy applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.