home/glossary/organizational policy

organizational policy

nounverified·updated Aug 30, 2026

A formally documented set of management directives, issued at the enterprise or program level, that establishes the rules, constraints, roles, and responsibilities governing an organization's conduct in a given security or compliance domain. It sits at the top of the policy hierarchy—above issue-specific and system-specific policies—and is technology-agnostic, expressing *what* must be done rather than *how*; lower-level standards, guidelines, and procedures derive their authority from it. In practice, controls frameworks invoke it as the baseline against which individual behaviors, configurations, accounts, or processes are evaluated for conformance, so that a finding of "violation of organizational policy" signals a deviation from these enterprise-level rules rather than from any single technical standard or system setting.

MWELegacy lexicon import

Senses

NIST SP 800-171r3attested usage reviewer confirmed

No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.

Classifications

Entity Type

Requirement95%llm-generatedllm:claude-haiku-4-5
?unassignedlast reviewed

Sensitivity

Internal75%llm-generatedllm:claude-haiku-4-5
?unassignedlast reviewed

Information Class

unclassified

Variants

plural
organizational policies
possessive
organizational policy's
pluralpossessive
organizational policies'