GlossaryGlossary

Security policy

A security policy is an approved statement of direction and expected behavior for protecting an organization's systems, data, and operations.

August 31, 2026Updated August 2026
Security policiesSecurity governanceFramework readiness

A security policy explains what an organization expects people and teams to do to manage security risk.

A clear policy usually defines:

  • Purpose and scope
  • Roles and accountability
  • Required controls or behaviors
  • Exceptions and approval rules
  • Review and maintenance expectations
  • Related procedures and evidence

A policy is not the same as a step-by-step procedure. It sets direction and requirements; procedures explain how work is performed. A good policy reflects the organization’s actual systems, roles, risk, and operating model instead of copying generic wording.

See the difference between a policy, standard, procedure, and guideline.