SlideShare a Scribd company logo
2
Most read
3
Most read
4
Most read
Security Program and
Policies
Principles and Practices
by Sari Stern Greene
Chapter 2: Policy Elements and Style
Copyright 2014 Pearson Education, Inc.l 2
Objectives
❑ Distinguish between a policy, a standard, a
baseline, a procedure, a guideline, and a plan
❑ Identify policy elements
❑ Include the proper information in each element of
a policy
❑ Know how to use “plain language”
Policy Hierarchy
■ Policies reflect the guiding principles and
organizational objectives
■ Policies need supporting documents for
context and application
❑ Standards, baselines, guidelines, and procedures
support policy implementation
■ The relationship between a policy and its
supporting documents is known as the policy
hierarchy
Copyright 2014 Pearson Education, Inc.l 3
Copyright 2014 Pearson Education, Inc.l 4
Policy Hierarchy cont.
■ Standards
❑ Dictate specific minimum requirements in policies
❑ They are specific
❑ Determined by management and can be changed
without the Board of Director authorization
■ Note that standards change more often than policies
■ Baselines
❑ An aggregate of implementation standards and
security controls for a specific category or
grouping (for example, Windows 7, smartphones,
and so on)
Copyright 2014 Pearson Education, Inc.l 5
Policy Hierarchy cont.
■ Guidelines
❑ Suggestions for the best way to accomplish a given
task
■ Guidelines are created primarily to assist users in their goal to
implement the policy
■ They are not mandatory
■ Procedures
❑ Method, or set of instructions, by which a policy is
accomplished
■ A step-by-step approach to implementation
❑ Four commonly used formats for procedures
■ Simple step, hierarchical, graphic, flowchart
Policy Hierarchy cont.
■ Plans and Programs
❑ Provide strategic and tactical instructions on how
to execute an initiative or respond to a situation
❑ Plans and programs are used interchangeably
❑ Plans are closely related to policies
Copyright 2014 Pearson Education, Inc.l 6
Copyright 2014 Pearson Education, Inc.l 7
Policy Format
■ The style and format of a policy will change
based on the target audience of said policy
■ Identify and understand the audience
■ Identify the culture shared by the target audience
❑ Plan the organization of the document before you
start writing it. Will it be…
■ One document with multiple sections?
❑ Consolidated policy section
■ Several individual documents?
❑ Singular policy
Copyright 2014 Pearson Education, Inc.l 8
Policy Components
■ Policy components
❑ Policies include many different sections and
components
❑ Each component has a different purpose
❑ Clearly identify the purpose of each element in the
planning phase before the writing part starts
Copyright 2014 Pearson Education, Inc.l 9
Version Control
■ Used to keep track of the changes to the policy
■ Usually identified by a number or letter code
■ Major revisions advance by a number or letter
❑ 1.0, 2.0, 3.0
■ Minor revisions advance by a subsection
❑ 1.1, 1.2, 1.3
■ Version control documentation includes:
❑ Change date
❑ Name of the person(s) making the change
❑ Brief synopsis of the change
❑ Who authorized the change
❑ The effective date of the change
Introduction
■ Provides context and meaning
■ Explains the significance of the policy
■ Explains the exemption process and the
consequences of noncompliance
■ Reinforces the authority of the policy
■ A separate document for a singular policy
■ Follows the version control table and serves
as a preface for consolidated policy
Copyright 2014 Pearson Education, Inc.l 10
Copyright 2014 Pearson Education, Inc.l 11
Policy Headings
■ Identifies the policy by name and provides an
overview of the policy topic or category
■ The format and content depends on the policy
format
❑ Singular policy includes:
■ Name of the organization or the division
■ Category, section, and subsection
■ Name of the author and effective date of the policy
■ Version number and approval authority
❑ Consolidated policy document
■ Heading serves as a section introduction and includes and
overview
Copyright 2014 Pearson Education, Inc.l 12
Policy Goals and Objectives
■ What is the goal of the policy?
■ Introduces the employee to the policy content
and conveys the intent of the policy
■ One policy may have several objectives
■ Singular policy objectives are located in the
policy heading or in the body of the document
■ Consolidated policy objectives are grouped
after the policy heading
Copyright 2014 Pearson Education, Inc.l 13
Policy Statement
❑ Why does the policy exist?
❑ What rules need to be followed?
❑ How will the policy be implemented?
Copyright 2014 Pearson Education, Inc.l 14
Policy Statement
■ Hig- level directive or strategic roadmap
❑ Focuses on the specifics of how the policy will be
implemented
❑ It’s a list of all the rules that need to be followed
❑ Constitutes the bulk of the policy
❑ Standards, procedures, and guidelines are not a
part of the Policy Statement. They can, however,
be referenced in that section
Copyright 2014 Pearson Education, Inc.l 15
Policy Exceptions
■ Not all rules are applicable 100% of the time
■ Exceptions do not invalidate the rules, as
much as they complement them by listing
alternative situations
■ Language used in this section must be clear,
accurate, and concise so as not to create
loopholes
■ Keep the number of exceptions low
Copyright 2014 Pearson Education, Inc.l 16
Policy Enforcement Clause
■ Rules and penalty for not following them
should be listed in the same document
■ The level of the severity of the penalty should
match the level of severity and nature of the
infraction
■ Penalties should not be enforced against
employees who were not trained on the
policy rules they are expected to follow
Administrative Notations
■ Provides a reference to an internal resource
or refers to additional information
■ Include regulatory cross-references, the
name of corresponding document (standard,
guideline, and so on), supporting
documentation (annual reports, job
descriptions), policy author name and contact
information
Copyright 2014 Pearson Education, Inc.l 17
Copyright 2014 Pearson Education, Inc.l 18
Policy Definitions
❑ The glossary of the policy document
❑ Created and included to further enhance
employee understanding of the policy and rules
❑ Renders the policy a more efficient document
❑ The target audience(s) should be defined prior to
the creation of the glossary
❑ Useful to show due diligence of the company in
terms of explaining the rules to the employees
during potential litigation
Writing Style and Technique
■ Sets the first impression
■ Policies should be written using plain
language
❑ Simplest, most straightforward way to express an
idea
❑ Follow The Plan Language Action and Information
Network (PLAIN) guidelines
Copyright 2014 Pearson Education, Inc.l 19
Copyright 2014 Pearson Education, Inc.l 20
Summary
❑ The structure of the policy documents ease the
maintenance and creation of the overall
document.
❑ A successful policy sets forth requirements
(standards), ways for employees to act according
to the policy (guidelines) and actual procedures.
❑ A policy is a complex set of individual documents
that build upon each other to convey the
message to all employees of the organization in
an efficient fashion.

More Related Content

PPT
Business Continuity Workshop Final
PPTX
Business continuity & disaster recovery planning (BCP & DRP)
PPTX
What is dr and bc 12-2017
PPTX
Bcp
PPTX
Crisis Management Strategies When Disaster Strikes
PPT
What is business continuity planning-bcp
PPTX
Risk and Business Continuity Management
PPTX
Business Continuity Planning
Business Continuity Workshop Final
Business continuity & disaster recovery planning (BCP & DRP)
What is dr and bc 12-2017
Bcp
Crisis Management Strategies When Disaster Strikes
What is business continuity planning-bcp
Risk and Business Continuity Management
Business Continuity Planning

What's hot (20)

PPTX
BCP Awareness
PDF
Crisis Management Powerpoint Presentation Slides
PPT
Emergency and Humanitarian Response
PPTX
Incident Command System
PDF
SOC 1 Overview
PPTX
Project Monitoring and Evaluation (M and E Plan) Notes
PPTX
Business continuity
PPT
Crisis management
ODP
Challenges of policy implementation in public organizations.ppt
PPT
Crisis management presentation
PDF
Project Management Framework
PPTX
What is GRC – Governance, Risk and Compliance
PDF
Disaster committee - roles & responsibilites
PPTX
Disaster Recovery Plan
PPTX
Business continuity & Disaster recovery planing
PPT
Change Management
PPTX
PPTX
Business Continuity & Disaster Recovery
PDF
IT-Centric Disaster Recovery & Business Continuity
PPTX
IAM Methods 2.0 Presentation Michael Nielsen Deloitte
BCP Awareness
Crisis Management Powerpoint Presentation Slides
Emergency and Humanitarian Response
Incident Command System
SOC 1 Overview
Project Monitoring and Evaluation (M and E Plan) Notes
Business continuity
Crisis management
Challenges of policy implementation in public organizations.ppt
Crisis management presentation
Project Management Framework
What is GRC – Governance, Risk and Compliance
Disaster committee - roles & responsibilites
Disaster Recovery Plan
Business continuity & Disaster recovery planing
Change Management
Business Continuity & Disaster Recovery
IT-Centric Disaster Recovery & Business Continuity
IAM Methods 2.0 Presentation Michael Nielsen Deloitte
Ad

Viewers also liked (17)

PPTX
Chapter 4: Governance and Risk Management
PPTX
Chapter 1: Understanding Policy
PPTX
Chapter 8: Communications and Operations Security
PPTX
Chapter 6: Human Resources Security
PPTX
Chapter 5: Asset Management
PPTX
Chapter 12: Business Continuity Management
PPTX
Chapter 9: Access Control Management
PPTX
Chapter 11: Information Security Incident Management
PPTX
Chapter 10: Information Systems Acquisition, Development, and Maintenance
PPTX
Chapter 13: Regulatory Compliance for Financial Institutions
PPTX
Chapter 7: Physical & Environmental Security
PPTX
Chapter 14: Regulatory Compliance for the Healthcare Sector
PPT
Chapter 3: Information Security Framework
PPTX
Chapter 15: PCI Compliance for Merchants
DOCX
What are policies procedures guidelines standards
PPTX
Characteristics of a good policy
PPT
POLICY MAKING PROCESS
Chapter 4: Governance and Risk Management
Chapter 1: Understanding Policy
Chapter 8: Communications and Operations Security
Chapter 6: Human Resources Security
Chapter 5: Asset Management
Chapter 12: Business Continuity Management
Chapter 9: Access Control Management
Chapter 11: Information Security Incident Management
Chapter 10: Information Systems Acquisition, Development, and Maintenance
Chapter 13: Regulatory Compliance for Financial Institutions
Chapter 7: Physical & Environmental Security
Chapter 14: Regulatory Compliance for the Healthcare Sector
Chapter 3: Information Security Framework
Chapter 15: PCI Compliance for Merchants
What are policies procedures guidelines standards
Characteristics of a good policy
POLICY MAKING PROCESS
Ad

Similar to Chapter 2: Policy Elements and style (20)

PPSX
Writing Effective Policies & Procedures2
PPSX
Writing Effective Policies & Procedures
PPTX
Writing and implementing HRM policies
PPTX
POLICY-FORMULATION-AND-DECISION-MAKING.pptx
PPTX
hrmp human resource policy
PPTX
Policy, formulation, implementation and evaluation
PPTX
Policy Writing (1).pptx for the ISMS and risk assessment GRC
PDF
Guide_to_Policy_Development_-_23_May_2017_-_Branding_Amendments_-_V7.pdf
PDF
Developing An Employee Handbook That Your Employees Will Read, Elrona D'Souza
PDF
How to Write Good Policies
PPTX
Business policy in healthcare management.pptx
PPTX
Policy formulation and evaluation
PPTX
PolicyPLUS Webinar - Effective Policy Writing and Management
DOCX
Directions  Respond to the Case Study below using the S.O.A.P. fo.docx
PPT
Info 442 chpt 1
PDF
Developing and Managing Educational Institution Policies
PPTX
UNITED KINGDOM.pptx
PPTX
How to Prepare a Policy and Procedure Manual
PDF
Nature and importance of business policy
PPTX
Compliance Policy Templates Framework, Implementation & Governance Essentials...
Writing Effective Policies & Procedures2
Writing Effective Policies & Procedures
Writing and implementing HRM policies
POLICY-FORMULATION-AND-DECISION-MAKING.pptx
hrmp human resource policy
Policy, formulation, implementation and evaluation
Policy Writing (1).pptx for the ISMS and risk assessment GRC
Guide_to_Policy_Development_-_23_May_2017_-_Branding_Amendments_-_V7.pdf
Developing An Employee Handbook That Your Employees Will Read, Elrona D'Souza
How to Write Good Policies
Business policy in healthcare management.pptx
Policy formulation and evaluation
PolicyPLUS Webinar - Effective Policy Writing and Management
Directions  Respond to the Case Study below using the S.O.A.P. fo.docx
Info 442 chpt 1
Developing and Managing Educational Institution Policies
UNITED KINGDOM.pptx
How to Prepare a Policy and Procedure Manual
Nature and importance of business policy
Compliance Policy Templates Framework, Implementation & Governance Essentials...

More from Nada G.Youssef (16)

PPTX
مجلة 1
PPTX
Chapter Tewlve
PPTX
Chapter Eleven
PPTX
Chapter Ten
PPTX
Chapter Nine
PPTX
Chapter Eight
PPTX
Chapter Seven
PPTX
Chapter Six
PPTX
Chapter Five
PPTX
Chapter Four
PPTX
Chapter Three
PPTX
Chapter Two
PPTX
Chapter one
PPTX
Preparatory Year of Saudi Electronic University
PPT
Chapter 12
PPTX
Chapter 11
مجلة 1
Chapter Tewlve
Chapter Eleven
Chapter Ten
Chapter Nine
Chapter Eight
Chapter Seven
Chapter Six
Chapter Five
Chapter Four
Chapter Three
Chapter Two
Chapter one
Preparatory Year of Saudi Electronic University
Chapter 12
Chapter 11

Recently uploaded (20)

PDF
Abdominal Access Techniques with Prof. Dr. R K Mishra
PPTX
master seminar digital applications in india
PDF
Physiotherapy_for_Respiratory_and_Cardiac_Problems WEBBER.pdf
PDF
Microbial disease of the cardiovascular and lymphatic systems
PPTX
Cell Structure & Organelles in detailed.
PDF
Complications of Minimal Access Surgery at WLH
PDF
3rd Neelam Sanjeevareddy Memorial Lecture.pdf
PDF
O7-L3 Supply Chain Operations - ICLT Program
PPTX
PPT- ENG7_QUARTER1_LESSON1_WEEK1. IMAGERY -DESCRIPTIONS pptx.pptx
PDF
BÀI TẬP BỔ TRỢ 4 KỸ NĂNG TIẾNG ANH 9 GLOBAL SUCCESS - CẢ NĂM - BÁM SÁT FORM Đ...
PPTX
1st Inaugural Professorial Lecture held on 19th February 2020 (Governance and...
PPTX
Cell Types and Its function , kingdom of life
PDF
Chapter 2 Heredity, Prenatal Development, and Birth.pdf
PDF
Saundersa Comprehensive Review for the NCLEX-RN Examination.pdf
PDF
Insiders guide to clinical Medicine.pdf
PPTX
GDM (1) (1).pptx small presentation for students
PDF
grade 11-chemistry_fetena_net_5883.pdf teacher guide for all student
PPTX
Institutional Correction lecture only . . .
PPTX
PPH.pptx obstetrics and gynecology in nursing
PPTX
Microbial diseases, their pathogenesis and prophylaxis
Abdominal Access Techniques with Prof. Dr. R K Mishra
master seminar digital applications in india
Physiotherapy_for_Respiratory_and_Cardiac_Problems WEBBER.pdf
Microbial disease of the cardiovascular and lymphatic systems
Cell Structure & Organelles in detailed.
Complications of Minimal Access Surgery at WLH
3rd Neelam Sanjeevareddy Memorial Lecture.pdf
O7-L3 Supply Chain Operations - ICLT Program
PPT- ENG7_QUARTER1_LESSON1_WEEK1. IMAGERY -DESCRIPTIONS pptx.pptx
BÀI TẬP BỔ TRỢ 4 KỸ NĂNG TIẾNG ANH 9 GLOBAL SUCCESS - CẢ NĂM - BÁM SÁT FORM Đ...
1st Inaugural Professorial Lecture held on 19th February 2020 (Governance and...
Cell Types and Its function , kingdom of life
Chapter 2 Heredity, Prenatal Development, and Birth.pdf
Saundersa Comprehensive Review for the NCLEX-RN Examination.pdf
Insiders guide to clinical Medicine.pdf
GDM (1) (1).pptx small presentation for students
grade 11-chemistry_fetena_net_5883.pdf teacher guide for all student
Institutional Correction lecture only . . .
PPH.pptx obstetrics and gynecology in nursing
Microbial diseases, their pathogenesis and prophylaxis

Chapter 2: Policy Elements and style

  • 1. Security Program and Policies Principles and Practices by Sari Stern Greene Chapter 2: Policy Elements and Style
  • 2. Copyright 2014 Pearson Education, Inc.l 2 Objectives ❑ Distinguish between a policy, a standard, a baseline, a procedure, a guideline, and a plan ❑ Identify policy elements ❑ Include the proper information in each element of a policy ❑ Know how to use “plain language”
  • 3. Policy Hierarchy ■ Policies reflect the guiding principles and organizational objectives ■ Policies need supporting documents for context and application ❑ Standards, baselines, guidelines, and procedures support policy implementation ■ The relationship between a policy and its supporting documents is known as the policy hierarchy Copyright 2014 Pearson Education, Inc.l 3
  • 4. Copyright 2014 Pearson Education, Inc.l 4 Policy Hierarchy cont. ■ Standards ❑ Dictate specific minimum requirements in policies ❑ They are specific ❑ Determined by management and can be changed without the Board of Director authorization ■ Note that standards change more often than policies ■ Baselines ❑ An aggregate of implementation standards and security controls for a specific category or grouping (for example, Windows 7, smartphones, and so on)
  • 5. Copyright 2014 Pearson Education, Inc.l 5 Policy Hierarchy cont. ■ Guidelines ❑ Suggestions for the best way to accomplish a given task ■ Guidelines are created primarily to assist users in their goal to implement the policy ■ They are not mandatory ■ Procedures ❑ Method, or set of instructions, by which a policy is accomplished ■ A step-by-step approach to implementation ❑ Four commonly used formats for procedures ■ Simple step, hierarchical, graphic, flowchart
  • 6. Policy Hierarchy cont. ■ Plans and Programs ❑ Provide strategic and tactical instructions on how to execute an initiative or respond to a situation ❑ Plans and programs are used interchangeably ❑ Plans are closely related to policies Copyright 2014 Pearson Education, Inc.l 6
  • 7. Copyright 2014 Pearson Education, Inc.l 7 Policy Format ■ The style and format of a policy will change based on the target audience of said policy ■ Identify and understand the audience ■ Identify the culture shared by the target audience ❑ Plan the organization of the document before you start writing it. Will it be… ■ One document with multiple sections? ❑ Consolidated policy section ■ Several individual documents? ❑ Singular policy
  • 8. Copyright 2014 Pearson Education, Inc.l 8 Policy Components ■ Policy components ❑ Policies include many different sections and components ❑ Each component has a different purpose ❑ Clearly identify the purpose of each element in the planning phase before the writing part starts
  • 9. Copyright 2014 Pearson Education, Inc.l 9 Version Control ■ Used to keep track of the changes to the policy ■ Usually identified by a number or letter code ■ Major revisions advance by a number or letter ❑ 1.0, 2.0, 3.0 ■ Minor revisions advance by a subsection ❑ 1.1, 1.2, 1.3 ■ Version control documentation includes: ❑ Change date ❑ Name of the person(s) making the change ❑ Brief synopsis of the change ❑ Who authorized the change ❑ The effective date of the change
  • 10. Introduction ■ Provides context and meaning ■ Explains the significance of the policy ■ Explains the exemption process and the consequences of noncompliance ■ Reinforces the authority of the policy ■ A separate document for a singular policy ■ Follows the version control table and serves as a preface for consolidated policy Copyright 2014 Pearson Education, Inc.l 10
  • 11. Copyright 2014 Pearson Education, Inc.l 11 Policy Headings ■ Identifies the policy by name and provides an overview of the policy topic or category ■ The format and content depends on the policy format ❑ Singular policy includes: ■ Name of the organization or the division ■ Category, section, and subsection ■ Name of the author and effective date of the policy ■ Version number and approval authority ❑ Consolidated policy document ■ Heading serves as a section introduction and includes and overview
  • 12. Copyright 2014 Pearson Education, Inc.l 12 Policy Goals and Objectives ■ What is the goal of the policy? ■ Introduces the employee to the policy content and conveys the intent of the policy ■ One policy may have several objectives ■ Singular policy objectives are located in the policy heading or in the body of the document ■ Consolidated policy objectives are grouped after the policy heading
  • 13. Copyright 2014 Pearson Education, Inc.l 13 Policy Statement ❑ Why does the policy exist? ❑ What rules need to be followed? ❑ How will the policy be implemented?
  • 14. Copyright 2014 Pearson Education, Inc.l 14 Policy Statement ■ Hig- level directive or strategic roadmap ❑ Focuses on the specifics of how the policy will be implemented ❑ It’s a list of all the rules that need to be followed ❑ Constitutes the bulk of the policy ❑ Standards, procedures, and guidelines are not a part of the Policy Statement. They can, however, be referenced in that section
  • 15. Copyright 2014 Pearson Education, Inc.l 15 Policy Exceptions ■ Not all rules are applicable 100% of the time ■ Exceptions do not invalidate the rules, as much as they complement them by listing alternative situations ■ Language used in this section must be clear, accurate, and concise so as not to create loopholes ■ Keep the number of exceptions low
  • 16. Copyright 2014 Pearson Education, Inc.l 16 Policy Enforcement Clause ■ Rules and penalty for not following them should be listed in the same document ■ The level of the severity of the penalty should match the level of severity and nature of the infraction ■ Penalties should not be enforced against employees who were not trained on the policy rules they are expected to follow
  • 17. Administrative Notations ■ Provides a reference to an internal resource or refers to additional information ■ Include regulatory cross-references, the name of corresponding document (standard, guideline, and so on), supporting documentation (annual reports, job descriptions), policy author name and contact information Copyright 2014 Pearson Education, Inc.l 17
  • 18. Copyright 2014 Pearson Education, Inc.l 18 Policy Definitions ❑ The glossary of the policy document ❑ Created and included to further enhance employee understanding of the policy and rules ❑ Renders the policy a more efficient document ❑ The target audience(s) should be defined prior to the creation of the glossary ❑ Useful to show due diligence of the company in terms of explaining the rules to the employees during potential litigation
  • 19. Writing Style and Technique ■ Sets the first impression ■ Policies should be written using plain language ❑ Simplest, most straightforward way to express an idea ❑ Follow The Plan Language Action and Information Network (PLAIN) guidelines Copyright 2014 Pearson Education, Inc.l 19
  • 20. Copyright 2014 Pearson Education, Inc.l 20 Summary ❑ The structure of the policy documents ease the maintenance and creation of the overall document. ❑ A successful policy sets forth requirements (standards), ways for employees to act according to the policy (guidelines) and actual procedures. ❑ A policy is a complex set of individual documents that build upon each other to convey the message to all employees of the organization in an efficient fashion.