Home > Ask the Security Experts > Questions & Answers > Differentiating between policies, standards, procedures and technical controls
Ask The Security Expert: Questions & Answers
EMAIL THIS

Differentiating between policies, standards, procedures and technical controls

PJ Varrassi EXPERT RESPONSE FROM: PJ Varrassi

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site
>
QUESTION POSED ON: 19 February 2001

What are the differences among policies, standards, procedures and technical controls?



Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


Policies

Policies are long-term, high-level management instructions on how the organization is to be run and generally are driven by legal concerns (due diligence). Policies reflect an organization's goals, objectives, culture and are intended for broad audiences. They also are mandatory and are applicable to anyone -- employee, contractor, temporary, etc. Special approval if the policy is not to be followed (an exception) should be documented. (Yes, a policy for exceptions is necessary!). Policies drive standards, procedures and technical controls. Example: Passwords will be used.

Standards

Standards define the process or rules to be used to support the policy such as system-design models or specific software or methodologies. Standards can be directed to a broad audience or limited to specific groups or individuals (i.e., software developers), are of limited duration and reflect organizational change or environmental changes. Like policies, standards are mandatory and require special approval if the standard is not to be followed. Example: Passwords will be constructed of 6-8 alpha-numeric characters.

Procedures

Procedures are specific instructions (ordered tasks) for performing some function or action. Procedures are of a somewhat short duration, are mandatory and they reflect organizational change or environmental changes. Example: To change your password, type your old password, then a front slash and then your new password.

Technical controls

Technical controls are mechanisms used to regulate the operations to meet policy requirements (countermeasures). Technical controls can be volitile particularly in the distributed environment when hackers are gracious enough to find holes in technology and point them out to the user community!




Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Find Security Solutions for Your Business
Targeted Security Channel Tips for Resellers, Integrators and Consultants
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts