Four useful distinctions
- Policy: states the organisation’s intent, expectations and responsibilities.
- Standard: sets specific requirements that must be met.
- Procedure: describes the steps for carrying out a task.
- Guideline: offers recommended ways of working and supports judgement.
A fictional access-management example
A policy requires appropriate access. A standard requires MFA for remote access. A procedure explains how access is approved and removed. A guideline helps someone choose a suitable authentication method.
Keeping documents useful
Documentation should be understandable, owned, maintained and easy to find. A document alone does not prove that a control operates effectively; implementation and review matter.
Terminology can vary between organisations. The important point is to make the purpose and authority of each document clear.