CISSP GLOSSARY · RISK MANAGEMENT & GOVERNANCE

Security policy

The top of the governance document hierarchy: a mandatory, high-level statement of management intent, implemented through standards and procedures and advised by guidelines.

A security policy is the highest-level governance document in an organisation’s security programme: a mandatory, strategic statement of management’s intent that defines what must be protected (often via data classification), who is responsible, and the consequences of non-compliance. It is deliberately high-level and technology-neutral so it survives tooling changes. Beneath it sit three further document types: standards, procedures, and guidelines, each more specific than the last.

The hierarchy’s compliance status decides exam answers. Policies are mandatory and broad. Standards are mandatory and specific: they name required technologies and configurations, such as full-disk encryption of a stated strength on every laptop. Procedures are mandatory and step-by-step: the exact instructions for performing a task. Guidelines are the odd one out: discretionary recommendations and good practice that staff should follow but are not compelled to. Baselines, where they appear, are the mandatory minimum configuration level, a form of standard. Publishing and enforcing this hierarchy is part of demonstrating due care.

Exam relevance: if a scenario asks which document expresses management’s intent, the answer is the policy; a named mandatory technology or configuration is a standard; step-by-step instructions are a procedure; anything recommended but optional is a guideline. The confusable pair is standard versus guideline: both are specific, but only the standard is mandatory, so the discriminator is compulsion, not detail. All four documents sit in the administrative, directive family of control types.