home/glossary/security policy

security policy

nounid 4079·updated May 9, 2026
candidate

A set of criteria for the provision of security services. It defines and constrains the activities of a data processing facility in order to maintain a condition of security for systems and data.

polysemousMWE

Classifications

Entity Type

Requirement90%rule-basedr:entity.requirement.policy.v1

Sensitivity

unclassified

Information Class

unclassified

Variants

plural
security policies
possessive
security policy's
pluralpossessive
security policies'

Framework definitions

SANS Glossary of Security Terms1 senseview framework →
§1
A set of rules and practices that specify or regulate how a system or organization provides security services to protect sensitive and critical system resources.
National Initiative for Cybersecurity Careers and Studies (NICCS) Cybersecurity Lexicon1 senseview framework →
§1 · extended_definition_available
A rule or set of rules that govern the acceptable use of an organization's information and services to a level of acceptable risk and the means for protecting the organization's information assets.
NIST Cybersecurity Framework1 senseview framework →
§1
The statement of required protection of the information objects that documents an organization's philosophy of managing, protecting, and distributing its computing and information assets. The set of security rules enforced by the system's security features.
FFIEC IT Examination Handbook - Audit, April 20121 senseview framework →
§1
The statement of required protection of the information objects that documents an organization's philosophy of managing, protecting, and distributing its computing and information assets. The set of security rules enforced by the system's security features.
NISTIR 7298: Glossary of Key Information Security Terms, Revision 23 sensesview framework →
§1
The statement of required protection of the information objects.
§2 · sense_2_pending_review
A set of criteria for the provision of security services. It defines and constrains the activities of a data processing facility in order to maintain a condition of security for systems and data.
§3 · sense_3_pending_review
A set of criteria for the provision of security services.
CNSSI-4009 (Glossary of Information Assurance Terms)1 senseview framework →
§1
A set of criteria for the provision of security services.
NIST SP 800-531 senseview framework →
§1
A set of criteria for the provision of security services.
NIST SP 800-371 senseview framework →
§1
A set of criteria for the provision of security services.
NIST SP 800-271 senseview framework →
§1
The statement of required protection of the information objects.
FIPS PUB 1881 senseview framework →
§1
A set of criteria for the provision of security services. It defines and constrains the activities of a data processing facility in order to maintain a condition of security for systems and data.

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships