TechKnowSurge
CompTIA Security+ 5.1 CompTIA CySA+ 1.5 CompTIA Security+ 5.4 CompTIA Security+ 1.1 CompTIA CySA+ 2.4
InteractiveSecurityFree

Policy Hierarchy Sorter

Sort governance document descriptions into the five-tier hierarchy: Policy, Standard, Procedure, Guideline, or Control.

Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

Every item here is a piece of a security program, and the bin you are asked for is not what the item is about — it is what the item does. Read each one and ask which job it is doing. A Policy directs: management states an intent or assigns a responsibility, in language broad enough to survive a change of vendor, and it does not tell you a number. A Standard requires: it takes the policy's intent and pins it to something specific and testable — a length, an algorithm, a deadline — and compliance with it is not optional. A Procedure instructs: it is ordered, it has steps, and someone can follow it without judgment. A Guideline suggests: it is the only tier here that you may decline, and its wording gives it away every time — consider, recommended, best practice, though not required. A Control enforces: it is the safeguard actually in place, running, doing the work that the documents above it merely describe. The single hardest distinction in this activity, and the one worth slowing down for, is Standard versus Control, because they can carry almost identical words. Two of the items are a deliberate near-pair: a requirement that production databases be patched within 30 days of a critical CVE, and an automated patch deployment within 72 hours of one. Both name patching, both name CVEs, both name a deadline. The first is a sentence in a document that says what must be true — Standard. The second is a mechanism that is running right now and would keep running if every copy of the document were deleted — Control. That is the test: could you delete this and still have it? If yes, it is a document. If deleting it would change what the systems actually do, it is a control. The same test separates the other Control items — multi-factor authentication enforced on privileged accounts and a firewall rule blocking port 23 — from the Standards that would have called for them. Two other traps are worth naming. The Policy items are easy to mistake for Standards because two of them contain the word must; must is not the tell, specificity is, and neither of those items names a number, a protocol, or a tool. And the four-step phishing item is one Procedure, not four — a procedure is the whole ordered sequence, and its steps are not separate documents. One note for the exam room: this five-tier framing is the common one and matches how most security programs are documented, but CompTIA Security+ SY0-701 objective 5.1 groups guidelines together with policies in its own subtopic list and treats controls under objective 1.1 instead. The distinctions you are drilling here are the same ones the exam tests; only the grouping on the objective sheet differs.

What you'll learn

Aligned to

CompTIA Security+
5.1 Summarize elements of effective security governance.
5.4 Summarize elements of effective security compliance.
1.1 Compare and contrast various types of security controls.
CompTIA CySA+
1.5 Explain the importance of efficiency and process improvement in security operations.
2.4 Given a scenario, recommend controls to mitigate attacks and software vulnerabilities.

Key terms

Security Policy
A formal document that defines an organization's security goals, rules, and responsibilities.
Standard
A mandatory, specific requirement derived from a policy that defines how the policy is to be implemented.
Procedure
A detailed, step-by-step set of instructions for carrying out a specific task in alignment with policies and standards.
Guideline
A recommended, non-mandatory suggestion that provides flexible guidance for implementing policies and standards.
Control
A measurable outcome or requirement used to verify that an organization is meeting its cybersecurity standards and can provide evidence of compliance.
Security Control
Any safeguard or countermeasure — whether technical, physical, or administrative — implemented to protect the confidentiality, integrity, and availability of systems and data. Security controls are classified by function (preventative, detective, corrective) and type (technical, physical, administrative).
Information Security Policy
ISP
A governing document that consolidates an organization's security policies into a single overarching framework, setting the tone for how security operations are conducted.
Acceptable Use Policy
AUP
A documented policy that defines the rules and expectations for how employees and internal users may use organizational systems and resources. An AUP establishes the grounds for disciplinary or legal action if violated.
Compliance
The act of adhering to the laws, regulations, standards, and internal policies that govern how an organization handles data and security. Compliance programs use audits and controls to demonstrate that requirements are being met.
Security Framework
A structured set of guidelines, best practices, and standards used as a starting point for designing and implementing a security program, such as the NIST Cybersecurity Framework.

Topics

Interactive Categorize

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →