Security policies define organizational goals, while standards provide the specific, measurable requirements used to achieve them. Together, they form the foundation for consistent, auditable security practices across areas like password management, access control, physical security, and encryption.
Policies and Standards
If the policy is the blueprint, it's what we want to achieve, the layout of what we are creating, however we need a standard: the quality in which we want to reach. A standard sets what those qualities are. Standards are typically going to be a much longer list of what it is that we're going to achieve, and setting that bar for what we're going to achieve.
So here are some examples of policies and standards. I'm going to use the word control right now as well; we're going to use those interchangeably at times.
So in this case right here we have a policy that says we're going to practice secure passwords. And then the standard for that, or one of the many standards, is going to be, well, we're going to update recommendations yearly. So that's going to be a standard that we're going to have. We're going to actually go out and research what is the new current recommendations for passwords, and we're going to take a look at it on a yearly basis and integrate that into our password policy.
Then we take a look here: we want a robust access control. Well, what does that mean? Well, our standard says, well, maybe we're going to audit rules on a quarterly basis. This is just one of many different standards that we would have for that policy.
Maybe we have a policy that says we're going to have robust monitoring. Well, what does that mean? Well, the standard sets that all accessways will be monitored 24/7.
Maybe we have a standard that says we're going to use up-to-date encryption. Well, our standard is going to be that we're going to update the encryption standards on a yearly basis, so we're going to research what is the current recommendations and implement that within our organization.
Here's a real brief list of password standards that's recommended in 2024. So we enable show passwords, use a password manager, store secrets using salting or hashing, blck after multiple attempts, employ two-factor multifactor authentication. So it doesn't really matter if you understand what each one of these are or not, but the point with this is that we set these more direct standards of what we're going to live up to.
Examples of standards that we'd have for access control would be, what kind of access control are we going to use? Are we going to use rule-based access control, rule-based access control, mandatory access control? So what are we going to follow with that? What kind of systems are we going to apply those to? What do credentials look like? What is the account life cycle for our different accounts? Do we do audits on that? So we get into details around the standards of access control.
With physical security, what are the methods that we're going to use? Are we going to use cameras, guards, locks? Are we going to have zones, and what do those zones look like? Are we going to allow visitors? Are we going to have certain sections that are going to be visitors? How are we going to handle breaches?
And there's lots of different encryption standards out there, so what is the acceptable encryption standards that we're going to use for the company? Where are those going to be applied? How are we going to manage the keys for those encryption standards?
Ultimately our standards are going to be what we measure against, on whether we're achieving our policies or not.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →