Procedures
Before you learn about procedures, you need to have an understanding of something that antecedes a procedure in the document hierarchy—a process. According to Merriam-Webster’s dictionary, “a process is a series of actions or operations conducing to an end.” In the case of information security, that end is to ensure compliance with a policy. According to Merriam-Webster, a procedure is also a particular way of accomplishing something or acting. In the case of information security, this refers to a specific, detailed series of actions that staff members must take in order to implement a process and comply with a process and its governing policy. The following figure represents the process of a defense contractor who needs to certify at CMMC Maturity Level 1 (ML 1):
Figure 3.1: Hierarchy of documents