TechKnowSurge
ISC2 CC 1.3 ISC2 CC 1.4 NIST 800-53 PM-1 NIST CSF GV.PO-01 ISC2 CC 2.1 NIST CSF GV.PO-02 NIST 800-53 PM-9 Cisco CCST Cybersecurity 4.3
VideoSecurityFree

Administrative Controls - Policies, Standards, Procedures, Guidelines, and Controls

A security program depends on a clear hierarchy of governance documents — policies, standards, procedures, guidelines, and controls — each serving a distinct role in defining and enforcing an organization's cybersecurity expectations. Understanding how these elements relate to one another is foundational to building and operating an effective security program.

Complete this video to capture a CTF flag worth 1 point.

About this video

Cybersecurity governance is structured around five distinct but interconnected concepts: policies, standards, procedures, guidelines, and controls. Policies sit at the top of this hierarchy and are typically authored by executive leadership or a board of directors. They establish the broad intent of the security program — what the organization is committed to doing — without prescribing specific actions. Their language is intentionally high-level, which means the details must be defined further down the hierarchy. Standards translate policy intent into concrete, mandatory requirements that the organization must meet. A single policy can give rise to many standards, each addressing a specific area of security practice. Procedures then take those standards and break them down into the actual step-by-step processes that staff execute to stay compliant. Unlike standards, guidelines are not mandatory — they are advisory recommendations that help practitioners make sound judgment calls when situations are ambiguous or require discretion. Controls occupy a unique position in this framework and are sometimes used interchangeably with standards, though they serve a distinct purpose. A control defines the measurable outcome that proves compliance — the specific, quantifiable result an organization must demonstrate to show that its policies and standards are being followed in practice. For example, specifying that 95 percent of systems must be patched within 30 days, and that any unpatched system must be removed from the network within 60 days, is a control. Controls are what auditors examine when assessing a security program, because they produce verifiable evidence that the organization is doing what it claims to do. Together, these five elements form the governance backbone of any mature cybersecurity program.

What you'll learn

What's covered

Policies Standards Procedures Guidelines Controls

Aligned to

ISC2 CC
1.3 Understand governance concepts
1.4 Understand cybersecurity controls
2.1 Plan Governance, Risk, and Compliance (GRC)
NIST 800-53
PM-1 Information Security Program Plan
PM-9 Risk Management Strategy
NIST CSF
GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced.
GV.PO-02 Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission.
Cisco CCST Cybersecurity
4.3 Explain risk management

Key terms

Security Policy
A formal document that defines an organization's security goals, rules, and responsibilities.
Standard
A mandatory, specific requirement derived from a policy that defines how the policy is to be implemented.
Procedure
A detailed, step-by-step set of instructions for carrying out a specific task in alignment with policies and standards.
Guideline
A recommended, non-mandatory suggestion that provides flexible guidance for implementing policies and standards.
Control
A measurable outcome or requirement used to verify that an organization is meeting its cybersecurity standards and can provide evidence of compliance.
Baseline
A documented set of minimum security standards or performance metrics used as a reference point.

Topics

Administrative Controls Security Policies Security Governance Cybersecurity Program Management Security Standards Security Procedures

Transcript

One of the things that a security program does is establish policies, standards, procedures, guidelines and controls. But what are all those things?

What each term means

All these come together to create the expectations of what the company or the organization is going to do, how it's going to perform, and in this case from a cyber security standpoint.

First of all, what needs to be set is the big overall scoping. What are we trying to accomplish? That's what policies do. Policies are set by the execs or higher up — the board of directors, somewhere at a higher level sets the policy of what we are trying to accomplish. We're trying to accomplish cyber security, but what is the big overall scoping? What are we trying to do?

Then we get into, how are we going to accomplish that? What are the standards that we are going to hold the company to? That's where the standards come into play. Where there are quite a few policies, there are a lot of standards: for each one of these policies you could have many different standards. The standards are going to be created by the security team, of what is going to be expected from the company, and it's going to get a lot more detailed with it.

From the standards of what we're trying to accomplish, we're going to develop procedures. The procedures are the processes that we are going to use, that the individuals are going to carry out, to implement the standards, to make sure we're following the standards.

Then we get into the guidelines. The guidelines are something that is not necessarily steadfast. It's not like a standard, where we have to meet the standard. It's not like a procedure, where we have got to follow this procedure. A guideline is more of suggestions on ways that we can implement it for the best success.

Controls

Let's address controls a little separately here. Controls can be a little bit trickier to define, and if you look at different resources out there, there are some different perspectives of what controls are. I'm going to go over three different definitions of it, or three different perspectives of what a control is. The first two are going to be what some perspectives are out there, and the third one is going to be the actual definition of what a control is.

First of all, one thing that people view controls as is that all of these things are controls. So it's just a general term that's used about how you're going to manage the cyber security program of the company or organization.

The next definition of controls is going to be that it's synonymous with standards. A lot of people use these terms interchangeably, and the reason why is because there are a lot of similarities between controls and standards. Standards set whatever that bar is going to be — that's what a standard sets. Controls do the same thing, but they do it to another degree.

So that's our third definition. A control is what your outcome is going to be. A control defines what the end expectation is going to be, or how you are going to measure all of this. It'll be more clear as we go over the examples of what a control is and how it takes the standards and defines them to a greater degree.

A baking example

Let's go over a baking example to see really what these terms mean.

First of all, I am going to have a policy. I'm going to have a policy for my family that I'm going to bake delicious desserts on a regular basis. Some key things to this: number one, it has got to be delicious. There's some interpretation that happens here, some vagueness that happens here that I'm going to have to further define as we go along. The next thing is dessert — I'm not specifying cakes, just that I'm going to cook desserts. They could be donuts, they could be pies, they could be cakes; there's a big range of what we can accomplish with this. And then it needs to be on a regular basis. I don't define how regular it needs to be, but I'm going to say it's going to be on a regular basis.

Next comes the standard. What is my standard? I could have lots of standards with this. One week maybe I do a cake, the next week I'm going to do donuts, the next week I'm going to do pies. So I could have lots of standards that fall under this to meet this policy. But in this particular case, I just took out one of those and I have one standard here: that I'm going to do a cake on a monthly basis. So I'm further defining what this standard is going to be, and I'm going to bake a cake on a monthly basis. I'm still specifying that it's going to be delicious here and that the whole family can enjoy it.

What is the procedure, then? The procedure is going to be what the process is that I'm actually going to do to follow through with this. Maybe I'm going to put something on my calendar as part of the procedure to make sure that it happens, or the recipe that I'm going to follow. There are a lot of different ways that I could go with this, but essentially it's the process that I'm going to go through to make sure that I'm following the standard: that I'm doing it on a monthly basis, that it's going to be delicious, that I'm going to follow the recipe, and that it's going to be on the calendar.

Then I'm going to have some guidelines. The guidelines are stuff that's not so prescriptive. It's things that are just going to help me out along the way. Maybe one of the guidelines is that I'm going to preheat the oven before mixing the ingredients. This is going to save me time — an order of operations here — so that way I'm not mixing all the ingredients and then having to wait for the oven to heat up. So it can just be a guideline of how to improve the experience or how to meet the rest of this criteria.

And then I have a control. The control, once again, is the little bit trickier one here, but think about measurable outcomes in the end. How am I going to actually know that I've accomplished the goal? So I'm going to write out the control saying: cakes will be baked on a monthly basis that the whole family would rate at least a 7 out of 10 on a deliciousness scale. Now I have something specific around that deliciousness, how delicious it's going to be.

And what do I have to do to prove this? In this case, maybe I send out a survey, or maybe I just do it verbally and say, okay, how did we like this? I baked a different cake this time, what would you rate it? Oh, you rated it as a six. Well, we didn't accomplish this goal this month, and so maybe I have to bake a different cake that would be rated higher. Maybe I bake a cake that I've baked in the past that I know the family would enjoy. So this is the control, and it's a measurable outcome at the end that we will use as a measuring stick to see if we are following through with what we say we're going to follow through with.

A patching example

This is a cyber security course, so we should apply this to something more technical. Here's an example of patching.

One of the policies that we may have is: we will perform maintenance on all hardware and software. Once again it's more of a vague statement, it's more of an upper level. This could even be more general than that. With policies there's a lot of leeway — it could just be, we have a cyber security program and we're going to make things secure, or we're going to follow the industry standards of what's expected from a cyber security standpoint, or fill in the blanks. In this example right here I just say, we will perform maintenance on all hardware and software.

One of the many standards that we have to meet this policy is a standard that says machines will be patched on a monthly basis.

What are the procedures? These are the actual steps that we are going to follow through to patch this. We're going to log into the patching server. We are going to research any updates that are presented to us. We're going to approve those updates. We're going to roll things out. These are all the steps that we're going to go through to make sure that the machines are patched.

What are the guidelines? One of the things that we need to do is research updates to see if it's an update we actually want to roll out. What's not part of this is: how do we rate whether we want to roll out a patch or not? So we have a guideline that says, approve all updates that have no known issues. I look out there and I say, oh, this patch doesn't have any known issues, I'm going to approve it. Or maybe it does — maybe it has some known issues. Then I need to assess: is this something where it's worth the risk in rolling this out even though there's a known issue, or is it better to hold back? I need to assess that. It's a judgment call, and this guideline helps me out with that judgment call. And then if there's still an issue, if I'm still unsure, I can seek guidance from the rest of the team to see what they say about it. So I can go and do that and we could all vote, or we can all go through the process to see whether we should roll this patch out or not.

Then what is the control? Once again, the control is what our desired outcome is. It's probably not reasonable to make sure that 100% of our machines are done on a monthly basis, so we need to get a little more granular with this. What is the actual expectation? We can at least hit 95% of the machines. So 95% of the machines must be patched within a month, and then any machines that are not patched within 60 days we have to remove from the network — whether we're removing them from Active Directory or removing them so they can't access the network. We could define that further as well.

Anyway, we have some sort of standards here, and then we need proof that we're actually following these standards, that we're actually following these controls. So maybe a printout or report of the patching from the patching software that says where all the machines are at from a patching perspective, to make sure that we're following this. It's something that I can turn over to, let's say, an auditing agency. That's where these controls really come into play: an auditing agency can come in and say, what are your controls? Are they appropriate for the size of business and type of business that you are? And are you actually following them? Show us proof that you are actually following through with these controls. That's what a control is: that I can present proof to show that I am actually doing what I say I'm going to do.

So there you have it. The policies set the direction of where we're heading with cyber security. The standards are what we have to meet to meet those policies, those expectations. The procedures are the process we're going to use to meet those standards. The guidelines are there to help us make determinations, make judgment calls. And the controls are that final outcome: what we are measuring in the end to prove that we're following through with what we say we're going to follow through with, that we are doing cyber security correctly.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →