What is a security policy?
D1 ยท General ยท CompTIA Security+ SY0-701A security policy is a high-level formal document that defines an organization's overall approach to information security โ articulating management's intent, security requirements, roles and responsibilities, and the consequences of non-compliance.
Policy hierarchy: Policy (high-level, why) โ Standard (specific requirements, what) โ Guideline (recommendations, how โ optional) โ Procedure (step-by-step instructions, how exactly).
Examples: Acceptable Use Policy (AUP), Password Policy, Data Classification Policy, BYOD Policy.
Policy hierarchy: Policy (high-level, why) โ Standard (specific requirements, what) โ Guideline (recommendations, how โ optional) โ Procedure (step-by-step instructions, how exactly).
Examples: Acceptable Use Policy (AUP), Password Policy, Data Classification Policy, BYOD Policy.
Know the policy hierarchy: Policy โ Standard โ Guideline โ Procedure. Policies are mandatory (enforced). Guidelines are recommendations (optional). An AUP defines acceptable use of company systems and is typically required of all employees. Security policies must be reviewed and updated regularly.