What is the Difference Between Policy vs Procedure?

Опубликовано: 05 Октябрь 2024
на канале: Alexander C. Hubbard
577
25

This is a rather frequent question, what is the difference between a policy and a procedure?

Polices are the guidelines for the way your organization may tackle a certain task. Let's say your organization has a policy for endpoint protection right? That policy might say "all endpoints must have antivirus, a firewall turned on, drive encryption enable and MFA" - The policy is going to govern how the endpoints are protected, but it's not going to spell out how that is accomplished.

That is where the procedure comes into play. The procedures cover "how" the policy is to be implemented. So your procedure for endpoint protection might read something like "First we install CrowdStrike (A/V), then we enable the local Windows Firewall, enable BitLocker and install Duo for MFA" - something along those lines. It's going to spell out what steps need to be taken to ensure the policy is met.

#vciso #cybersecurity #policies #procedures #ciso #infosec #achubbard #alexhubbard #achsysadmin #thecybersecuritymindset