What are security policies? Think of them as an organizational decree—a stated intent to achieve some ideal outcome or end state, similar to a law. These documents are meant to govern organizational behavior at a high level. Also similar to laws, they do not specify how their objectives are to be met—that is the purpose of a different document, which will be covered in the Procedures section.
A security policy serves several purposes. As mentioned previously, policies set high-level goals regarding their subject area. Organizations rely on security policies to decide how they should deploy limited resources and which success metrics will be applied. Security policies also provide a template for different related documents, such as processes and procedures. Procedure documents use policy directives as guiding principles to form more concrete instructions as to how policy objectives will be met within the organization.
These types of documents will be discussed...