Skip to content

Policies & governance

Security governance defines who decides, what’s expected, and how it’s measured. Policies are the instrument: documents that set the rules and turn security strategy into concrete obligations for the whole organization. Without them, security depends on individual good judgment.

Policy WHAT and WHY: high-level principles and rules (approved by management)
Standard concrete, mandatory requirements (e.g. "MFA on all access")
Procedure HOW: detailed steps to meet a standard (step by step)
Guideline recommendations (non-mandatory) of good practice
# policy -> standard -> procedure -> guideline (from strategic to operational)
- Information Security Policy (the "umbrella")
- acceptable use (AUP), access control, passwords/MFA, information classification
- incident management, continuity (grc-bcp), backup, remote work/BYOD
- vendor/third-party management, secure development (dso-sdlc), privacy (grc-rgpd)
- management SUPPORT (tone at the top): without it, policies aren't followed
- roles and responsibilities (CISO, security committee, asset/risk owners)
- RACI: who is Responsible, Accountable, Consulted, Informed for each thing
- metrics and reporting to management; alignment with business objectives
1. draft (clear, applicable, aligned with frameworks and law)
2. approve (management) and communicate (people must know it -> grc-concienciacion)
3. enforce (technical and organizational controls that back it)
4. review periodically (annually or on change) -> continuous improvement
# a policy no one knows or enforces is useless: communication + enforcement
- policies copied without adapting -> inapplicable, nobody follows them
- too detailed/rigid -> become obsolete or get breached
- without technical backing -> "the policy says so" but nothing prevents it
- without review -> describe a reality that no longer exists
  • Regulatory non-compliance aggravated by the lack of documented, approved policies.
  • Breaches where the absence of a vendor policy allowed uncontrolled third-party access.
  • Programs that fail for lack of management support, no matter how much technical effort.
  • Management support and roles/responsibilities (RACI) defined
  • Coherent document hierarchy (policy/standard/procedure/guideline)
  • Key policies present (security, access, incidents, vendors, privacy)
  • Policies backed by technical controls (not just paper)
  • Communicated and trained (Awareness & training)
  • Aligned with frameworks and law (Frameworks (ISO 27001, NIST, ENS, CIS), GDPR & privacy)
  • Periodic review and continuous improvement