home/glossary/information security policy

information security policy

nounverified·updated May 9, 2026

The rules and guidelines of an organization on how to ensure the confidentiality, integrity, and availability of the organization's information.

MWENIST Cybersecurity Framework

Senses

National Initiative for Cybersecurity Careers and Studies (NICCS) Cybersecurity Lexicon

An aggregate of directives, regulations, rules, and practices that prescribe how an organization manages, protects, and distributes information.

NISTIR 7298: Glossary of Key Information Security Terms, Revision 2

Aggregate of directives, regulations, rules, and practices that prescribes how an organization manages, protects, and distributes information.

Classifications

Entity Type

Requirement90%rule-basedr:entity.requirement.policy.v1
?unassignedlast reviewed

Sensitivity

unclassified

Information Class

unclassified

Variants

synonym
policies for information security
plural
information security policies
possessive
information security policy's
pluralpossessive
information security policies'