Guidelines
Guidelines are sometimes referred to as standards. As with standards, they are collections of best practices but are often too specific to a niche aspect of cybersecurity to be useful as a framework. The difference between standards and guidelines is that they are leveraged to inform specific aspects of cybersecurity programs. Take a look at an example use of guidelines in Figure 3.1. You may leverage the best practice in NIST SP 800-100 Information Security Handbook: A Guide for Managers as a guideline while researching and writing your security policies in a general sense. Through your research, determine a password policy appropriate to your organization. You can leverage a different set of best practices in NIST SP 800-63-3 Digital Identity Guidelines as a guideline to write your password policy, process, and procedures.