What is the real difference between a policy, a standard and a procedure?

A policy establishes the organisation's high-level intent and direction for information security, defining 'what' must be achieved. A standard provides mandatory requirements and specifications, detailing 'how' to implement a policy consistently across the organisation. A procedure offers granular, step-by-step instructions, outlining 'who' performs specific tasks, 'when,' and 'how' to ensure repeatable execution. These documents form a hierarchical structure, translating strategic objectives into actionable steps for compliance and control.

In practice, these documents form a critical hierarchy within an Information Security Management System (ISMS) or control framework. A policy, often approved by senior management, articulates the organisation's commitment and overarching principles, such as an Information Security Policy or an Acceptable Use Policy. It sets the scope and tone without prescribing specific technologies or methods. Standards then translate these policies into concrete, mandatory requirements. For instance, a policy stating 'all sensitive data must be encrypted' would be supported by a standard specifying 'AES-256 encryption must be used for data at rest on all production servers,' providing technical or operational baselines. Procedures further break down these standards into detailed, sequential instructions, guiding individuals through specific tasks like 'how to configure AES-256 encryption on a new server' or 'the steps for incident response notification.' This ensures consistency and reduces ambiguity in daily operations.

Practitioners often err by conflating these document types or failing to maintain their distinct purposes, leading to unmanageable or ineffective documentation. A common pitfall is creating policies that are too prescriptive, or procedures that lack sufficient detail, making them difficult to audit or enforce. For ISO 27001 and SOC 2 compliance, organisations must demonstrate that policies are established, communicated, and reviewed, and that procedures are followed consistently. Auditors will assess not only the existence of these documents but also their effectiveness in practice. Regular review and updates are crucial to ensure alignment with evolving threats, technological changes, and regulatory requirements, preventing documentation from becoming obsolete or misaligned with actual operational practices. Clear differentiation ensures that strategic intent flows down to operational execution, providing a robust framework for governance, risk, and compliance.

Sources

  • ISO/IEC 27001:2022, Clause 5.2, Policy for information security
  • ISO/IEC 27001:2022, Clause 7.5, Documented information
  • AICPA Trust Services Criteria, Common Criteria (CC1.1, CC3.1, CC4.1)

Related