home/glossary/security policy

security policy

nounverified·updated May 9, 2026

A set of criteria for the provision of security services. It defines and constrains the activities of a data processing facility in order to maintain a condition of security for systems and data.

polysemousMWENISTIR 7298: Glossary of Key Information Security Terms, Revision 2

Senses

SANS Glossary of Security Terms

A set of rules and practices that specify or regulate how a system or organization provides security services to protect sensitive and critical system resources.

National Initiative for Cybersecurity Careers and Studies (NICCS) Cybersecurity Lexiconextended definition available

A rule or set of rules that govern the acceptable use of an organization's information and services to a level of acceptable risk and the means for protecting the organization's information assets.

NIST Cybersecurity Framework

The statement of required protection of the information objects that documents an organization's philosophy of managing, protecting, and distributing its computing and information assets. The set of security rules enforced by the system's security features.

NISTIR 7298: Glossary of Key Information Security Terms, Revision 2

The statement of required protection of the information objects.

NISTIR 7298: Glossary of Key Information Security Terms, Revision 2sense 3 pending review

A set of criteria for the provision of security services.

NIST SP 800-171r3attested usage pack match

No definition is given in NIST SP 800-171r3. The term is attested in use at 6 citations in that document; a definition is pending curation.

Classifications

Entity Type

Requirement90%rule-basedr:entity.requirement.policy.v1
?unassignedlast reviewed

Sensitivity

unclassified

Information Class

unclassified

Variants

plural
security policies
possessive
security policy's
pluralpossessive
security policies'