TechKnowSurge
ISC2 CISSP 1.6 CompTIA Security+ 5.1 NIST CSF GV.PO-01 NIST 800-53 PL-1 NIST 800-53 AC-1 ISC2 CISSP 2.6 NIST CSF PR.AA-05
VideoSecurityFree

Standards

Security policies define organizational goals, while standards provide the specific, measurable requirements used to achieve them. Together, they form the foundation for consistent, auditable security practices across areas like password management, access control, physical security, and encryption.

Complete this video to capture a CTF flag worth 1 point.

About this video

Security governance relies on two distinct but closely related concepts: policies and standards. A policy defines what an organization wants to achieve — its high-level security objectives and intent. A standard specifies how that objective will be met in measurable, operational terms. While a policy might state that the organization will practice secure password management, the supporting standards define exactly what that means in practice, such as conducting annual reviews of current password recommendations, requiring multi-factor authentication, and storing credentials using salting or hashing. Standards are typically more numerous and detailed than the policies they support, and organizations may maintain many standards for a single policy area. This structure applies consistently across security domains. Access control policies, for instance, are backed by standards that define which access control models will be used, how credentials are structured, what the account lifecycle looks like, and how often access rules are audited. Physical security policies are supported by standards covering surveillance methods, zone definitions, visitor protocols, and breach response procedures. Encryption policies are governed by standards that specify acceptable algorithms, where encryption is applied, and how cryptographic keys are managed and rotated. Ultimately, standards serve as the benchmark against which an organization measures its own compliance — they make policies actionable and auditable, turning broad security intent into concrete, enforceable practice.

What you'll learn

What's covered

Policies and Standards

Aligned to

ISC2 CISSP
1.6 Develop, document, and implement security policy, standards, procedures, and guidelines
2.6 Determine data security controls and compliance requirements
CompTIA Security+
5.1 Summarize elements of effective security governance.
NIST CSF
GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced.
PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties.
NIST 800-53
PL-1 Policy and Procedures
AC-1 Policy and Procedures

Key terms

Security Policy
A formal document that defines an organization's security goals, rules, and responsibilities.
Access Control
A security mechanism that restricts access to resources based on policies, roles, or identity.
Encryption
The process of converting readable data into an unreadable format using an algorithm and key to prevent unauthorized access.
Multi-Factor Authentication
MFA
An authentication method that requires users to provide two or more verification factors to gain access.
Role-Based Access Control
RBAC
An access control model that assigns permissions based on a user's role within an organization.
Baseline
A documented set of minimum security standards or performance metrics used as a reference point.
Security Standard
A measurable, specific requirement that defines how a security policy is to be implemented and achieved within an organization.

Topics

Security Standards Security Policies Password Management Access Control Encryption Physical Security Governance Risk Compliance

Transcript

Policies and Standards

If the policy is the blueprint, it's what we want to achieve, the layout of what we are creating, however we need a standard: the quality in which we want to reach. A standard sets what those qualities are. Standards are typically going to be a much longer list of what it is that we're going to achieve, and setting that bar for what we're going to achieve.

Examples of Policies and Standards

So here are some examples of policies and standards. I'm going to use the word control right now as well; we're going to use those interchangeably at times.

So in this case right here we have a policy that says we're going to practice secure passwords. And then the standard for that, or one of the many standards, is going to be, well, we're going to update recommendations yearly. So that's going to be a standard that we're going to have. We're going to actually go out and research what is the new current recommendations for passwords, and we're going to take a look at it on a yearly basis and integrate that into our password policy.

Then we take a look here: we want a robust access control. Well, what does that mean? Well, our standard says, well, maybe we're going to audit rules on a quarterly basis. This is just one of many different standards that we would have for that policy.

Maybe we have a policy that says we're going to have robust monitoring. Well, what does that mean? Well, the standard sets that all accessways will be monitored 24/7.

Maybe we have a standard that says we're going to use up-to-date encryption. Well, our standard is going to be that we're going to update the encryption standards on a yearly basis, so we're going to research what is the current recommendations and implement that within our organization.

A Brief List of Password Standards

Here's a real brief list of password standards that's recommended in 2024. So we enable show passwords, use a password manager, store secrets using salting or hashing, blck after multiple attempts, employ two-factor multifactor authentication. So it doesn't really matter if you understand what each one of these are or not, but the point with this is that we set these more direct standards of what we're going to live up to.

Standards for Access Control, Physical Security and Encryption

Examples of standards that we'd have for access control would be, what kind of access control are we going to use? Are we going to use rule-based access control, rule-based access control, mandatory access control? So what are we going to follow with that? What kind of systems are we going to apply those to? What do credentials look like? What is the account life cycle for our different accounts? Do we do audits on that? So we get into details around the standards of access control.

With physical security, what are the methods that we're going to use? Are we going to use cameras, guards, locks? Are we going to have zones, and what do those zones look like? Are we going to allow visitors? Are we going to have certain sections that are going to be visitors? How are we going to handle breaches?

And there's lots of different encryption standards out there, so what is the acceptable encryption standards that we're going to use for the company? Where are those going to be applied? How are we going to manage the keys for those encryption standards?

Ultimately our standards are going to be what we measure against, on whether we're achieving our policies or not.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →