Policy Hierarchy
Definition
The layered document set that translates governance intent into operational requirements. Tiers typically run: information security policy, topic-specific policies, standards, procedures, and guidelines. Each tier must be consistent with and traceable to the tier above.
- Top tier
- Information security policy
- Lower tiers
- Topic-specific policies, standards, procedures, guidelines
- Requirement
- Each tier traceable to the tier above
Common questions
What is the practical difference between a standard and a procedure in this hierarchy?+
A standard sets a measurable, mandatory requirement, such as a minimum password length, while a procedure is the step-by-step instruction for how staff actually meet that requirement in a specific system, so standards say what is required and procedures say how to achieve it.
Why do auditors care about traceability between hierarchy tiers?+
An organization can otherwise accumulate procedures and standards that drift from stated policy intent over time, and demonstrating that every lower-tier document maps back to an approved policy statement is how an audit confirms the governance framework is actually coherent rather than just paperwork.
Related terms
- CISO (Chief Information Security Officer)
- The senior executive responsible for developing and maintaining the information security programme. The CISO reports to the board or a board committee...
- Governance, Risk, and Compliance (GRC)
- An integrated discipline that combines governance structures, risk management processes, and compliance monitoring into a unified programme. GRC platforms and frameworks allow...
- Risk Appetite
- The amount and type of risk an organisation is willing to accept in pursuit of its objectives, as defined by its governing...
- Security Governance
- The set of structures, roles, policies, and accountability mechanisms by which an organisation directs, controls, and monitors its information security activities. Governance...
- Three Lines of Defence
- A governance model that separates security responsibility into three distinct layers: operational management that owns controls (first line), risk and compliance functions...