security policy
Term · Cybersecurity · MLC-T-CYB-003833
1. The set of laws, rules, and practices that regulate how an organization manages, protects, and distributes sensitive information.
2. The statement of required protection for the information objects.
3. A set of rules that governs all aspects of security-relevant system and system component behavior.
4. A set of rules that governs all aspects of security-relevant system and system element behavior.
5. Security policies define the objectives and constraints for the security program. Policies are created at several levels, ranging from organization or corporate policy to specific operational constraints (e.g., remote access). In general, policies provide answers to the questions “what” and “why” without dealing with “how.” Policies are normally stated in terms that are technology-independent.
| Identifier | MLC-T-CYB-003833 |
|---|---|
| Field | Cybersecurity |
| References | CNSSI 4009-2022; NIST SP 800-137; NIST SP 800-175A; NIST SP 800-30 Rev. 1; NIST SP 800-39; NIST SP 800-53 Rev. 5; NIST SP 800-57 Part 2 Rev.1; NIST SP 800-192; NISTIR 7316; NIST SP 800-53 Rev. 5; NIST SP 800-160v1r1; NIST SP 800-82r3; NIST CSRC Glossary |
Record as JSON
{
"id": "MLC-T-CYB-003833",
"term": "security policy",
"field": "Cybersecurity",
"definition": "1. The set of laws, rules, and practices that regulate how an organization manages, protects, and distributes sensitive information.\n\n2. The statement of required protection for the information objects.\n\n3. A set of rules that governs all aspects of security-relevant system and system component behavior.\n\n4. A set of rules that governs all aspects of security-relevant system and system element behavior.\n\n5. Security policies define the objectives and constraints for the security program. Policies are created at several levels, ranging from organization or corporate policy to specific operational constraints (e.g., remote access). In general, policies provide answers to the questions “what” and “why” without dealing with “how.” Policies are normally stated in terms that are technology-independent.",
"references": [
"CNSSI 4009-2022; NIST SP 800-137; NIST SP 800-175A; NIST SP 800-30 Rev. 1; NIST SP 800-39; NIST SP 800-53 Rev. 5; NIST SP 800-57 Part 2 Rev.1",
"NIST SP 800-192; NISTIR 7316",
"NIST SP 800-53 Rev. 5",
"NIST SP 800-160v1r1",
"NIST SP 800-82r3",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/security-policy/"
}
Record 3,833 of 4,693 in Cybersecurity terminology (MLC-0102). Request the full dataset.