← Core Concepts

Core Concepts

Security Documentation

The different jobs of policies, standards, procedures and guidelines.

Governance

Four useful distinctions

  • Policy: states the organisation’s intent, expectations and responsibilities.
  • Standard: sets specific requirements that must be met.
  • Procedure: describes the steps for carrying out a task.
  • Guideline: offers recommended ways of working and supports judgement.

A fictional access-management example

A policy requires appropriate access. A standard requires MFA for remote access. A procedure explains how access is approved and removed. A guideline helps someone choose a suitable authentication method.

Keeping documents useful

Documentation should be understandable, owned, maintained and easy to find. A document alone does not prove that a control operates effectively; implementation and review matter.

Terminology can vary between organisations. The important point is to make the purpose and authority of each document clear.