security policy
A set of criteria for the provision of security services. It defines and constrains the activities of a data processing facility in order to maintain a condition of security for systems and data.
Senses
A set of rules and practices that specify or regulate how a system or organization provides security services to protect sensitive and critical system resources.
A rule or set of rules that govern the acceptable use of an organization's information and services to a level of acceptable risk and the means for protecting the organization's information assets.
The statement of required protection of the information objects that documents an organization's philosophy of managing, protecting, and distributing its computing and information assets. The set of security rules enforced by the system's security features.
The statement of required protection of the information objects.
A set of criteria for the provision of security services.
No definition is given in NIST SP 800-171r3. The term is attested in use at 6 citations in that document; a definition is pending curation.
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- security policies
- possessive
- security policy's
- pluralpossessive
- security policies'