Governance Document Hierarchy
| Document | Description | Mandatory? | Level of Detail |
|---|---|---|---|
| Policy | High-level statement of intent and management direction. Sets "what must be done." | Yes | Low (general) |
| Standard | Specific requirements that support a policy. Defines "how exactly" something must be done. | Yes | High (specific) |
| Procedure | Step-by-step instructions for completing a specific task. | Yes | Highest (step-by-step) |
| Guideline | Recommended best practices. Not mandatory — advisory only. | No (advisory) | Varies |
| Baseline | Minimum security configuration for a system type. | Yes | System-specific |
Common Security Policies
- Acceptable Use Policy (AUP): Rules for how employees may use company IT systems and data
- Information Security Policy: Overall governance document for the security program
- Password Policy: Minimum length, complexity, history, and reset requirements
- Data Classification Policy: How data is classified and handled at each level
- Incident Response Policy: Roles and responsibilities for responding to security incidents
- BYOD Policy: Rules for personal devices accessing corporate resources
- Clean Desk Policy: Requires workstations to be clear of sensitive materials when unattended
- Social Media Policy: Controls what employees can post about the organization
Major Security Frameworks
| Framework | Purpose | Who Uses It |
|---|---|---|
| NIST CSF (Cybersecurity Framework) | Risk-based framework: Identify, Protect, Detect, Respond, Recover | All industries (US); voluntary but widely adopted |
| NIST SP 800-53 | Comprehensive security control catalog | US federal agencies; contractors |
| ISO/IEC 27001 | International standard for Information Security Management Systems (ISMS) | Global organizations; certifiable |
| ISO/IEC 27002 | Code of practice / guidelines for implementing ISO 27001 controls | Companion to 27001 |
| SOC 2 | AICPA audit standard for service organizations covering Trust Service Criteria (Security, Availability, Confidentiality, Processing Integrity, Privacy) | SaaS/cloud service providers |
| PCI DSS | Payment Card Industry Data Security Standard — 12 requirements for handling cardholder data | Any org handling credit/debit cards |
| HIPAA Security Rule | Requirements for protecting ePHI (electronic Protected Health Information) | US healthcare providers, insurers, business associates |
| CIS Controls | 18 prioritized security controls (formerly top 20) | Organizations of all sizes; free |
| MITRE ATT&CK | Knowledge base of adversary TTPs; used for threat modeling and detection gap analysis | SOC teams, threat hunters, red teams |
Legal Environment
- GDPR (EU General Data Protection Regulation): Protects personal data of EU residents; applies globally to orgs processing EU data; 72-hour breach notification; fines up to 4% global revenue
- CCPA (California Consumer Privacy Act): California privacy law; gives consumers rights over their data
- HIPAA: US healthcare privacy and security; 60-day breach notification for breaches affecting 500+ individuals
- COPPA: Protects personal data of children under 13 in the US
- SOX (Sarbanes-Oxley): Financial controls for public companies; IT general controls audit required
- FERPA: Protects student educational records
- Computer Fraud and Abuse Act (CFAA): US law criminalizing unauthorized computer access
Governance Structures
- CISO (Chief Information Security Officer): Owns the security program; reports to CIO or CEO/Board
- Security Steering Committee: Cross-functional group guiding security strategy
- Board-Level Oversight: Increasing requirement post-SEC cyber disclosure rules
- Security Operations Center (SOC): Operational team responsible for monitoring, detection, and response
- Risk Management Committee: Oversees enterprise risk including cyber risk
Exam Tip: Know the hierarchy: Policy (mandatory, high-level) → Standard (mandatory, specific) → Procedure (step-by-step) → Guideline (advisory). Framework questions: NIST CSF = voluntary; ISO 27001 = certifiable; PCI DSS = payment cards; HIPAA = healthcare. SOC 2 = service providers.