Security policies, standards, guidelines, and procedures

"The security program development process needs to be driven by the implementing company's security goals and objectives. These goals and objectives manifest themselves in a set of ICS security policies, which drive standards from which procedures and guidelines are derived."

As security policies and procedures are essential to the entire security program development process, it is important to clearly understand the difference between them.

Policies are high-level statements relating to the protection of systems and information across the organization. Policies should be set by the senior management.

Standards are specific low-level mandatory controls and activities that help enforce ...

Get Industrial Cybersecurity now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.