166 terms · 75/46/45
Defense № 042 · class: governance

Security Policies

Formal documents defining an organization's cybersecurity rules and standards.

Term

description · examples · notes

Formal documents defining an organization's cybersecurity rules and standards.

Description

Cover password policy, access policy, data classification, and acceptable use.

Hierarchy: policies (what) → standards (how much) → procedures (how) → guidelines (recommendations).

Must be approved by management and communicated to all employees.

Regular review and updates (minimum annually) are mandatory.

What people often say

  • A policy without enforcement and monitoring is just a document.
  • Overly complex policies are not followed — simplicity increases compliance.

Covers / does not cover

Covers

  • Defining security rules
  • Data and access classification
  • Employee obligations and responsibilities

Does not cover

  • Technical policy enforcement (tools and teams do that)
  • Automated detection of policy violations
  • Incident reaction (that is the IR plan)
Composite

Threats

reduces 4

Techniques

neutralizes 3

Techniques it neutralizes. Select one to open its page.