L20. Security Policies, Governance & Awareness Training
Course outlineLesson 20 of 20
Security policies define the rules of the road. Without clear policies, technical controls lack authority and employees lack guidance. This lesson covers the policy hierarchy, key policy types, and how to build a security-aware culture.
Security Policy Hierarchy
Policies are organized in a hierarchy from most authoritative to advisory:
| Level | Description | Example |
|---|---|---|
| Policy | High-level statement of intent; mandatory | "All data must be encrypted at rest" |
| Standard | Specific measurable requirements that implement policy | "AES-256 must be used for all data at rest" |
| Procedure | Step-by-step instructions for implementing a standard | "How to enable BitLocker on a Windows workstation" |
| Guideline | Recommended best practices; advisory, not mandatory | "Consider using a password manager" |
Key Security Policies
Acceptable Use Policy (AUP): defines what employees may and may not do with company systems. Must be signed by all users. Covers personal use, prohibited activities, monitoring disclosure. Incident Response Policy: defines who does what when an incident occurs; references the IR plan and playbooks. Data Classification Policy: defines classification levels and handling requirements for each level. Password Policy: minimum length, complexity, rotation, reuse restrictions, and lockout settings. BYOD Policy: requirements for personal devices accessing corporate resources (MDM enrollment, acceptable use, remote wipe consent). Clean Desk Policy: sensitive materials must be secured when unattended; reduces risk of shoulder surfing and physical theft.Due Care vs Due Diligence
Due diligence: researching and understanding risks before making a decision. Example: performing a vendor security assessment before signing a contract. Due care: taking ongoing reasonable action to protect assets. Example: applying security patches, maintaining backups, enforcing the AUP.Both are required to demonstrate that an organization acted reasonably in protecting assets.
Security Awareness Training
Effective awareness programs:
- Annual mandatory training for all employees
- Role-based training for high-risk roles (finance, IT, executives)
- Phishing simulations with immediate feedback and remedial training for clickers
- Metrics: track click rates on simulations over time (declining rate = effective training)
- Foster a "report, don't fear" culture: employees should feel safe reporting suspicious activity
- ✓Policy hierarchy: Policy (mandatory intent) > Standard (specific requirements) > Procedure (step-by-step) > Guideline (advisory)
- ✓AUP (Acceptable Use Policy) defines permitted and prohibited use of company systems; must be signed by all users
- ✓Due diligence = researching risks before acting; due care = ongoing reasonable protective action
- ✓Phishing simulation click rates measured over time are the primary metric for awareness training effectiveness
- ✓ISO 27001 is a certifiable ISMS standard; NIST CSF is a voluntary framework (neither replaces the other)
1. A company requires that all laptops use AES-256 encryption. This requirement is documented in a written document that all employees must follow. What type of document is this?
2. Before signing a contract with a cloud provider, a CISO reviews the provider's security certifications, penetration test reports, and audit findings. Which concept does this represent?
3. A security team sends simulated phishing emails to employees and tracks who clicks. Users who click receive immediate training. Over 12 months, the click rate drops from 22% to 4%. What does this indicate?
Recommended: Pluralsight
Turn your CompTIA Security+ concepts into passing marks: Pluralsight adds structured study plans, practice exams, and hands-on scenario labs.