Domain 2: Governance and Management of IT7 min · 3 questions

Policies, Standards, Procedures and Guidelines

Four documents that candidates blur together. The exam tests which is mandatory, which is specific, and which one management can change without going back to the board.

What this makes you able to do

Evaluate an organisation's policy framework and place a given document at the correct level of the hierarchy.

By the end you can

  • Order policy, standard, procedure and guideline by authority and specificity.
  • State which are mandatory and which are discretionary.
  • Determine the correct level at which to address a given control requirement.

Transcript

Policies, standards, procedures and guidelines. Four documents that candidates blur together, and the exam is precise about the differences, because their status is usually what the answer turns on.

Here is the situation. You ask to see the organisation’s rules on encryption, and you are handed four documents that contradict each other on the detail. One says data should be protected. One names an algorithm. One describes how to configure the tool. And one recommends a stronger cipher. Which one actually binds anyone?

The first cut is simple: which of these are mandatory, and which are discretionary. Three of the four compel you. One does not. Getting that split right resolves most questions at this level, so let us place each one.

They form a hierarchy, from highest authority and least specific, down to lowest authority and most specific. Policy sets the direction. Standard fixes the specific rule. Procedure gives the method. Guideline offers advice.

At the top, the policy. A high-level statement of management intent. Broad, enduring, and mandatory. Sensitive data must be protected in storage and transit. It says what and why, never how.

Beneath it, the standard. A mandatory, specific rule that supports the policy. Data at rest must be encrypted using A-E-S two fifty-six. Specific enough to test, and binding. Standards are where a policy’s intent becomes a measurable requirement.

Then the procedure. The step-by-step method for carrying out a task in line with the standards. To enable disk encryption, do the following. Mandatory in the sense that the task must be done this way, but operational rather than directional.

And at the bottom, the guideline. Discretionary advice and recommended practice. Consider rotating keys more often for high-value data. Helpful, not binding. The guideline is the one level that does not compel anyone. So: policies, standards and procedures are mandatory; guidelines are not.

Now, why the levels are separated, because this is a favourite exam scenario. A policy states enduring intent and rarely changes, which is why it sits high and is often board-approved. A standard carries the specific value that technology forces you to revisit, an algorithm, a key length, a version. So the algorithm belongs in a standard, beneath the policy, where management can update it as cryptography moves on without reopening a board-approved policy. Put the algorithm in the policy, and you must amend the policy every time the technology changes.

And the framework only works if each document is treated according to its level. A guideline enforced as if it were mandatory is a real finding, because it corrodes the whole structure. If a discretionary recommendation can get you disciplined, staff can no longer tell what is genuinely required, and truly mandatory standards lose their authority in the noise.

So the exam uses this in two ways. When a question hinges on whether something is binding, the level tells you: standard, procedure and policy bind, a guideline does not. And when a question asks where a specific value belongs, the answer is almost always a standard beneath the policy, so it can change as technology does.

Carry this away. A standard is mandatory and a guideline is not, a policy sets direction and a procedure sets method. When the answer hinges on whether something binds, or on where a value belongs, the level is the answer.

Knowledge check
0 / 3
  1. 1.Which of the following documents states the mandatory, specific rules that support a policy, such as the minimum password length an organisation requires?

  2. 2.Senior management wants to change the required encryption algorithm for stored data as technology evolves, without amending a board-approved document each time. At which level should the specific algorithm be set?

  3. 3.An IS auditor finds that a document labelled 'guideline' is being enforced as mandatory, and staff are disciplined for not following it. What is the auditor's MAIN concern?

Independent training produced by Marco Cavani. Not affiliated with, endorsed by, or sponsored by ISACA. CISA is a registered trademark of ISACA. Practice questions are written for this course and are not reproduced from ISACA materials.

Stay ahead of cyber threats

Get the latest cybersecurity reports, threat intelligence, and IT governance insights delivered straight to your inbox. No spam. Unsubscribe any time.

No spam. Unsubscribe at any time.