About this interactive
Every item here is a piece of a security program, and the bin you are asked for is not what the item is about — it is what the item does. Read each one and ask which job it is doing. A Policy directs: management states an intent or assigns a responsibility, in language broad enough to survive a change of vendor, and it does not tell you a number. A Standard requires: it takes the policy's intent and pins it to something specific and testable — a length, an algorithm, a deadline — and compliance with it is not optional. A Procedure instructs: it is ordered, it has steps, and someone can follow it without judgment. A Guideline suggests: it is the only tier here that you may decline, and its wording gives it away every time — consider, recommended, best practice, though not required. A Control enforces: it is the safeguard actually in place, running, doing the work that the documents above it merely describe. The single hardest distinction in this activity, and the one worth slowing down for, is Standard versus Control, because they can carry almost identical words. Two of the items are a deliberate near-pair: a requirement that production databases be patched within 30 days of a critical CVE, and an automated patch deployment within 72 hours of one. Both name patching, both name CVEs, both name a deadline. The first is a sentence in a document that says what must be true — Standard. The second is a mechanism that is running right now and would keep running if every copy of the document were deleted — Control. That is the test: could you delete this and still have it? If yes, it is a document. If deleting it would change what the systems actually do, it is a control. The same test separates the other Control items — multi-factor authentication enforced on privileged accounts and a firewall rule blocking port 23 — from the Standards that would have called for them. Two other traps are worth naming. The Policy items are easy to mistake for Standards because two of them contain the word must; must is not the tell, specificity is, and neither of those items names a number, a protocol, or a tool. And the four-step phishing item is one Procedure, not four — a procedure is the whole ordered sequence, and its steps are not separate documents. One note for the exam room: this five-tier framing is the common one and matches how most security programs are documented, but CompTIA Security+ SY0-701 objective 5.1 groups guidelines together with policies in its own subtopic list and treats controls under objective 1.1 instead. The distinctions you are drilling here are the same ones the exam tests; only the grouping on the objective sheet differs.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →