security policy
nouncandidate·updated May 9, 2026
A set of criteria for the provision of security services. It defines and constrains the activities of a data processing facility in order to maintain a condition of security for systems and data.
Framework senses
- §1
- A set of rules and practices that specify or regulate how a system or organization provides security services to protect sensitive and critical system resources.
National Initiative for Cybersecurity Careers and Studies (NICCS) Cybersecurity Lexicon1 senseview framework →
- §1 · extended_definition_available
- A rule or set of rules that govern the acceptable use of an organization's information and services to a level of acceptable risk and the means for protecting the organization's information assets.
- §1
- The statement of required protection of the information objects that documents an organization's philosophy of managing, protecting, and distributing its computing and information assets. The set of security rules enforced by the system's security features.
- §1
- The statement of required protection of the information objects that documents an organization's philosophy of managing, protecting, and distributing its computing and information assets. The set of security rules enforced by the system's security features.
- §1
- The statement of required protection of the information objects.
- §2 · sense_2_pending_review
- A set of criteria for the provision of security services. It defines and constrains the activities of a data processing facility in order to maintain a condition of security for systems and data.
- §3 · sense_3_pending_review
- A set of criteria for the provision of security services.
- §1
- A set of criteria for the provision of security services.
- §1
- A set of criteria for the provision of security services.
- §1
- A set of criteria for the provision of security services.
- §1
- The statement of required protection of the information objects.
- §1
- A set of criteria for the provision of security services. It defines and constrains the activities of a data processing facility in order to maintain a condition of security for systems and data.