Policies & governance
Security governance defines who decides, what’s expected, and how it’s measured. Policies are the instrument: documents that set the rules and turn security strategy into concrete obligations for the whole organization. Without them, security depends on individual good judgment.
The document hierarchy
Section titled “The document hierarchy”Policy WHAT and WHY: high-level principles and rules (approved by management)Standard concrete, mandatory requirements (e.g. "MFA on all access")Procedure HOW: detailed steps to meet a standard (step by step)Guideline recommendations (non-mandatory) of good practice# policy -> standard -> procedure -> guideline (from strategic to operational)Common policies
Section titled “Common policies”- Information Security Policy (the "umbrella")- acceptable use (AUP), access control, passwords/MFA, information classification- incident management, continuity (grc-bcp), backup, remote work/BYOD- vendor/third-party management, secure development (dso-sdlc), privacy (grc-rgpd)Security governance
Section titled “Security governance”- management SUPPORT (tone at the top): without it, policies aren't followed- roles and responsibilities (CISO, security committee, asset/risk owners)- RACI: who is Responsible, Accountable, Consulted, Informed for each thing- metrics and reporting to management; alignment with business objectivesA policy’s lifecycle
Section titled “A policy’s lifecycle”1. draft (clear, applicable, aligned with frameworks and law)2. approve (management) and communicate (people must know it -> grc-concienciacion)3. enforce (technical and organizational controls that back it)4. review periodically (annually or on change) -> continuous improvement# a policy no one knows or enforces is useless: communication + enforcementCommon mistakes
Section titled “Common mistakes”- policies copied without adapting -> inapplicable, nobody follows them- too detailed/rigid -> become obsolete or get breached- without technical backing -> "the policy says so" but nothing prevents it- without review -> describe a reality that no longer existsBlue Team / GRC
Section titled “Blue Team / GRC”- Start from management support and clear roles (CISO, risk owners, RACI).
- Clear, applicable, and backed policies with technical controls (not “paper”).
- Communicate and train (Awareness & training): an unknown policy isn’t followed.
- Align with frameworks and law (Frameworks (ISO 27001, NIST, ENS, CIS), GDPR & privacy) and review periodically.
Real cases and fines
Section titled “Real cases and fines”- Regulatory non-compliance aggravated by the lack of documented, approved policies.
- Breaches where the absence of a vendor policy allowed uncontrolled third-party access.
- Programs that fail for lack of management support, no matter how much technical effort.
Testing checklist
Section titled “Testing checklist”- Management support and roles/responsibilities (RACI) defined
- Coherent document hierarchy (policy/standard/procedure/guideline)
- Key policies present (security, access, incidents, vendors, privacy)
- Policies backed by technical controls (not just paper)
- Communicated and trained (Awareness & training)
- Aligned with frameworks and law (Frameworks (ISO 27001, NIST, ENS, CIS), GDPR & privacy)
- Periodic review and continuous improvement