Documented rules and guidelines governing how an organisation protects its information assets.
Security policies are documented rules and guidelines governing information protection within an organisation. Policies define what is required (acceptable use, password requirements, data handling); procedures describe how to comply. A policy framework typically includes an overarching information security policy supported by topic-specific policies (access control, incident response, data protection). Policies must be approved by management, communicated to staff, and regularly reviewed.
Why It Matters
The DSC Perspective:
Policies provide the foundation for security expectations. Without documented policies, requirements are unclear and enforcement is difficult. Policies are also compliance requirements—auditors will ask for them.
