Information Assurance: Managing Organizational IT Security Risks

Provide the fundamental concept of policies and their distinction from other concepts such as standards, guidelines, and procedures
Provide the intent and significance of establishing IA policies for an organization
Provide the mechanics of developing, communicating, and enforcing IA policies within an organization
Provide the basic structure and policy subjects for an organizational IA policy
First, it would be beneficial to begin with an understanding of the concept of a "policy" and how this definition distinguishes it from other commonly used terms. A distinction will be drawn between the concepts of "policies," "guidelines," "standards," "practices," and "procedures." Generally, an organization of any size or profit motive has a "purpose" that defines its basis for existence; a "philosophy" that defines its fundamental or core beliefs relative to the achievement of its purpose; and "premises" which are the assumptions about its opportunities, threats, geopolitical space environmental constraints, strengths, and weaknesses. "Policies," "guidelines," "standards," and "procedures" provide a means for an organization to support accomplishment of its purpose.
"Policies" are management instructions indicating how an organization is to be run. They are high-level statements intended to provide guidance to those who make decisions. They typically include general statements of goals, objectives, beliefs, ethics, and responsibilities and are expressed in ordinary business language that does not address implementation methods. Importantly, policies are regulatory or advisory in nature and require special approval when a worker wishes to take a contrary course of action. In this they differ from guidelines,...