Skip to content

Policy Hierarchy

Policy Hierarchy published on

A good hierarchy for InfoSec policies could are pointed out by the acloud.guru CISSP course.

This could be handy to revise your policies and name them appropriate. In ISO/IEC 27001 the naming of policies isn't that clear, so it's a good help:

  1. Policies: High-level, general and informative
  2. Standards: Mid-level, uniform and tactical
  3. Procedures: Low-level
  4. Guidelines Operational, e.g. how things to deploy
  5. Baselines: minium set level.