Policy control families
Creating your policy framework can be intimidating. Table 10.1 only shows a small snippet of what should be considered for policy documents, not to mention that the framework should include an exhaustive list of controls when starting out, as you may only have a handful of controls.
There are a few lists that can assist you when starting out creating your own framework. The Open Policy Framework is an open source project aimed at assisting policymakers. It lays out several control families that you can use to start your own framework. These include the following:
- Information security: The information security control family is aimed at data protection and acceptable use. Standards documents could include the acceptable use policy, encryption, data disposal, and information lifecycle management (ILM). The information security control family is meant to control and secure the organization’s sensitive information.
- Asset management: There is...