Skip to content

Policy Hierarchy

Definition

The layered document set that translates governance intent into operational requirements. Tiers typically run: information security policy, topic-specific policies, standards, procedures, and guidelines. Each tier must be consistent with and traceable to the tier above.

Top tier
Information security policy
Lower tiers
Topic-specific policies, standards, procedures, guidelines
Requirement
Each tier traceable to the tier above

Common questions

What is the practical difference between a standard and a procedure in this hierarchy?+

A standard sets a measurable, mandatory requirement, such as a minimum password length, while a procedure is the step-by-step instruction for how staff actually meet that requirement in a specific system, so standards say what is required and procedures say how to achieve it.

Why do auditors care about traceability between hierarchy tiers?+

An organization can otherwise accumulate procedures and standards that drift from stated policy intent over time, and demonstrating that every lower-tier document maps back to an approved policy statement is how an audit confirms the governance framework is actually coherent rather than just paperwork.

Related terms

CISO (Chief Information Security Officer)
The senior executive responsible for developing and maintaining the information security programme. The CISO reports to the board or a board committee...
Governance, Risk, and Compliance (GRC)
An integrated discipline that combines governance structures, risk management processes, and compliance monitoring into a unified programme. GRC platforms and frameworks allow...
Risk Appetite
The amount and type of risk an organisation is willing to accept in pursuit of its objectives, as defined by its governing...
Security Governance
The set of structures, roles, policies, and accountability mechanisms by which an organisation directs, controls, and monitors its information security activities. Governance...
Three Lines of Defence
A governance model that separates security responsibility into three distinct layers: operational management that owns controls (first line), risk and compliance functions...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.