TechKnowSurge
NIST CSF GV.PO-01 NIST 800-53 PL-1 ISC2 CC 1.3 CompTIA Security+ 5.1 NIST CSF GV.RR-02 NIST CSF ID.IM-01 CompTIA A+ Core 2 4.1
InteractiveSecurityFree

Write It Down or Set a Policy?

Is the organization missing a written process or a policy? Sort each problem.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

Without good documentation and clear policies, a security program has no real structure. Documentation is the record of how a process was done, what went wrong and what went right. Without it, every year's audit is reinvented from memory and last year's lessons are lost. With it, the next round starts from where the last one ended. Written processes are carried out the same way each time, errors can be seen and corrected, nobody reinvents the work, and other people can join in or take it over. Policies take documentation to the next level. They are governing principles, a blueprint: they say what the company is building toward, so everyone works to the same plan, the way plumbers, electricians and framers work from one set of drawings. Policies set the expectations of who is responsible for what, and that creates accountability. They may also be required by law, by regulation, or by the customers and vendors the company does business with. Policies guide standards, standards guide procedures, and guidelines help along the way. The next lesson takes that hierarchy apart.

What you'll learn

Aligned to

NIST CSF
GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced.
GV.RR-02 Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced.
ID.IM-01 Improvements are identified from evaluations.
NIST 800-53
PL-1 Policy and Procedures
ISC2 CC
1.3 Understand governance concepts
CompTIA Security+
5.1 Summarize elements of effective security governance.
CompTIA A+ Core 2
4.1 Given a scenario, implement best practices associated with documentation and support systems information management.

Key terms

Security Policy
A formal document that defines an organization's security goals, rules, and responsibilities.
Procedure
A detailed, step-by-step set of instructions for carrying out a specific task in alignment with policies and standards.
Standard
A mandatory, specific requirement derived from a policy that defines how the policy is to be implemented.
Compliance
The act of adhering to the laws, regulations, standards, and internal policies that govern how an organization handles data and security. Compliance programs use audits and controls to demonstrate that requirements are being met.

Topics

Security Policy Documentation Accountability Interactive Categorize

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →