Articles

Policy, standard, procedure, guideline: four levels of instruction

Policy states intent, standards bind, procedures give the steps, guidelines advise.

Reading: 6 minCybersecurity Governance

Article cover: Policy, standard, procedure, guideline: four levels of instruction

An organisation that wants a security decision to hold has to write it down, and not every written instruction does the same job. NIST’s introduction to information security separates four instruments: the policy, which states what the organisation wants, why, and who is accountable; the standard, which fixes a uniform way of doing something and is normally compulsory within the organisation; the procedure, which gives the detailed steps; and the guideline, which recommends where imposing a rule is not achievable, appropriate or cost-effective (NIST SP 800-12 Rev. 1, §5.1). Of the four, only the instruments a person can be held against are controls.

The model: four levels of instruction, from intent to action

policy       what and why, and who is accountable     broad; sets direction
    ↓
standard     which option is compulsory and uniform   normally binding in the org
    ↓
procedure    how to do it, step by step               detailed, per task
    ↓
guideline    what is recommended                      advisory; adaptation allowed

The four levels are not a ranking of importance or authority; they are a division of labour between the broad statement and the detail that implements it. SP 800-12 Rev. 1 says that because policy is written at a broad level, organisations also develop standards, guidelines and procedures to give users and managers a clearer approach to implementing it (§5.1). The lower the instrument, the more detail it carries, and the flexibility belongs at the bottom, in how a goal is met.

What each instrument commits you to

  1. Policy states intent and assigns accountability. Program policy creates the information security programme, sets its strategic direction and assigns resources for it; it defines the programme’s purpose and scope and assigns responsibility for implementation (§5.2).
  2. Issue-specific policy narrows the subject. Where the programme policy is silent, it addresses an area of current concern — the source’s examples range from internet access to email privacy and social media — and it is reviewed regularly because technologies change (§5.3).
  3. System-specific policy applies to one system. It sets security objectives commensurate with that system’s risk, and the more detailed its rules, the easier it is for administrators to tell when a violation has occurred (§5.4).
  4. Standards make a choice compulsory and uniform. A standard specifies uniform use of a technology, parameter or procedure where that uniformity benefits the organisation; standards are normally compulsory (§5.1).
  5. Procedures carry the steps. A procedure describes how to implement the applicable policies, standards and guidelines: the steps a user or operator follows to complete a task (§5.1).
  6. Guidelines advise where a rule does not fit. They help people secure their systems where imposing a standard is not achievable, appropriate or cost-effective, and they can be met in more than one way (§5.1).

The distinction this sheet owns: who each instrument binds

Instrument Question it answers Force Written for
Policy what and why, and who is accountable organisational commitment the whole organisation
Standard which uniform option is used normally compulsory within the organisation everyone the standard covers
Procedure how, step by step mandatory where it implements policy the role that performs the task
Guideline what is recommended advisory whoever decides in context

Two frameworks show the same layering from opposite directions. In NIST SP 800-53 Rev. 5 every control family opens with a -1 control — AC-1, AU-1 and the rest — normally titled POLICY AND PROCEDURES; it requires the organisation to develop, document and disseminate the family’s policy and the procedures that implement it, to designate an official to manage them, and to review and update both. SP 800-12 Rev. 1 states the same from the governing document’s side: policy controls are addressed by the -1 controls for every family in SP 800-53. In CSF 2.0 the layer is the Governance function’s Policy category, GV.PO: policy is established, communicated and enforced, resting on organisational context and strategy (GV.PO-01) and reviewed and updated as requirements, threats, technology and mission change (GV.PO-02).

A common misconception: “policy and procedure are the same thing”

The most common error is to treat the words as synonyms, or to assume that a more detailed policy is a safer one. The sources argue the opposite: because policy is written at a broad level, that breadth is what lets an organisation offer alternative ways of achieving the policy goal, and distinguishing policy from its implementation promotes flexibility and cost-effectiveness.

A second version of the mistake is to write a policy once. SP 800-53 Rev. 5 requires the policy and the procedures of each family to be reviewed and updated at an organisation-defined frequency and following defined events — assessment findings, incidents and breaches, or changes in laws and regulations. CSF 2.0 says the same in GV.PO-02.

The distinction matters operationally because of enforcement. A guideline leaves the decision in context, so it cannot be breached the way a standard can; a procedure is what an operator is measured against; a policy is what a manager is accountable for. A document mixing all four levels tells no one which applies to them.

What to remember

  • Policy states what and why, and who is accountable; it is broad.
  • Standards specify uniform use and are normally compulsory.
  • Procedures give the detailed steps that implement policy and standards.
  • Guidelines recommend where imposing a standard is not achievable, appropriate or cost-effective.
  • SP 800-53 expresses each family’s policy layer as its -1 control; CSF 2.0 GV.PO is its policy category.
  • A policy no one can be held against is a document, not a control.

Level and prerequisites

L1 — fundamentals: the vocabulary and the division of labour between the four instruments, with no procedure to write and no template to fill in. Prerequisites: none. Drafting policies, review cycles and exceptions are L2 material.

Where to go next

  • Cybersecurity Governance — the area this sheet belongs to.
  • The technical side of any standard belongs to Networking, Server & Virtualization or AI & LLM (roadmap §6).

References

  • NIST, An Introduction to Information Security (NIST SP 800-12 Rev. 1) — Chapter 5 Information Security Policy: the three policy types, §5.1 Standards, Guidelines, and Procedures, §5.2 Program Policy, §5.3 Issue-Specific Policy, §5.4 System-Specific Policy.
  • NIST, Security and Privacy Controls for Information Systems and Organizations (NIST SP 800-53 Rev. 5) — the -1 POLICY AND PROCEDURES control of each family, with AC-1 read as the reference example.
  • NIST, The NIST Cybersecurity Framework (CSF) 2.0 (NIST CSWP 29, 2024) — the Governance function’s Policy category GV.PO and its subcategories GV.PO-01 and GV.PO-02.