Information Security Policies, Procedures, and Guidelines
A security program is implemented through a specific set of policies, standards, and procedures:
- Policies: These are sets of ideas or strategies used as a basis for decision-making. They are high-level statements of direction made by management.
There can be multiple policies at the corporate level as well as at the department level. It should be ensured that department-wise policies are consistent and aligned with corporate-level policies.
- Standards: These are mandatory requirements to be followed to comply with a given policy, framework, certification, or regulation. Standards provide detailed directions for compliance.
A standard helps to ensure the efficiency and effectiveness of processes, resulting in reliable products or services. Standards are updated as and when required to incorporate new processes, technologies, and regulatory requirements.
A standard is a dynamic document and...