Policy, standards, and procedures
A security program is implemented through a specific set of policies, standards, and procedures. Let's understand how each one of these operates:
- Policies: A policy is a set of ideas or strategies that are used as a basis for decision making. They are the high-level statements of direction by management.
There can be multiple policies at the corporate level as well as the department level. It should be ensured that department-level policies are consistent and aligned with corporate-level policies.
- Standards: A standard is a mandatory requirement to be followed in order to comply with a given policy or framework or certification or regulation. A standard provides detailed directions to comply with the policy.
A standard helps to ensure an efficient and effective process, resulting in reliable products or services. Standards are updated as and when required to incorporate new processes, technology, and regulatory requirements.
A standard...