Policies, standards, procedures, and guidelines
A follow-on to the previous section is policies, standards, procedures, and guidelines. This section works hand-in-hand with baselining and holds extreme importance within an organization. It is critical that as part of your security program well-defined policies, standards, and procedures are in place and are followed by everyone. In addition, it is important that policies are signed off on and enforced by leadership. Without this support, it becomes more difficult to enforce and collectively get behind security from an organizational level.
Start by defining and creating your company policies. As a result, your standards can then be built to form the foundation of your baselines. Once these baselines are created, procedures and guidelines can be built to implement the baselines and help accomplish the end goal. Keeping this strategy in mind will drive compliance with your company policies.
The following section provides a brief...