Text Only Version

Policy Management & Compliance


The following defines the difference betwen Policies, Procedures, Guidelines, Standards, Principles, Best Practices and Frameworks.

Policy
  1. Senior managements directives to create an information resources security program, establish its goals, and assign responsibilities.
  2. Specific security rules for particular systems or specific managerial decisions, such as establishing an organizations electronic mail (e-mail) privacy policy or fax security policy

Policies contain the following information: Identify general areas of risk State generally how to address the risk. Provide a basis for verifying compliance through audits. Outline implementation and enforcement plans Balance protection with productivity. Policies are of three (3) types:

  1. Program policies address overall IT security goals and typically apply to all IT resources within an institution.
  2. System-specific address the IT security issues and goals of a particular system
  3. Issue-specific address particular IT security issues such as, Internet access, installation of unauthorized software or equipment, and sending/receiving e-mail attachments.
Procedure
A course of action or series of steps to implement and enforce policies.

Guideline
An indication of the scope and direction of policies and procedures. Guidelines contain the following information: Identify best practices to facilitate compliance Provide additional background or other relevant information

Standard
Standards contain the following information: Define minimum requirements designed to address certain risks Define specific requirements that ensure compliance with policies

Provide a basis for verifying compliance through audits Outline implementation and enforcements plans Balance protection with productivity

Principle
A statement that addresses a major issue or concern in campus IT security. The principles can be used to develop campus policies.

Best Practice
A process or practice that is known to produce optimal results in a similar environment.

Framework
A structure to facilitate the development of plans, policies and other documents.