organizational policy
A formally documented set of management directives, issued at the enterprise or program level, that establishes the rules, constraints, roles, and responsibilities governing an organization's conduct in a given security or compliance domain. It sits at the top of the policy hierarchy—above issue-specific and system-specific policies—and is technology-agnostic, expressing *what* must be done rather than *how*; lower-level standards, guidelines, and procedures derive their authority from it. In practice, controls frameworks invoke it as the baseline against which individual behaviors, configurations, accounts, or processes are evaluated for conformance, so that a finding of "violation of organizational policy" signals a deviation from these enterprise-level rules rather than from any single technical standard or system setting.