Policy and Strategy
Roger A. Grimes · 2017
This chapter focuses on standards, policies, procedures, frameworks, and laws considered in computer security. Standards are documented minimum norms, conventions, protocols, or requirements. A standard is often represented as a policy and further supported by procedures. Procedures are a documented sequence of steps designed to support standards and policies around deployment and operations. Procedures can change independently of policies and standards, for example, if a new software program requires different procedures. Creating standards and policies for the entire spectrum of computer security from scratch can be very difficult. Frameworks assist by demonstrating commonly supported standards, policies, formats, and a set of inclusive topics. A great example of a cybersecurity framework is NIST's Cybersecurity Framework. Standards and policies can be codified into legal regulations and laws. For example, companies wishing to process many common credit card types must follow the standards covered in the Payment Card Industry Security Standards Council's Data Security Standard.