Cyber Intelligence
Security Program Management & Oversight · 20% of exam

L20. Security Policies, Governance & Awareness Training

Course outlineLesson 20 of 20

Security policies define the rules of the road. Without clear policies, technical controls lack authority and employees lack guidance. This lesson covers the policy hierarchy, key policy types, and how to build a security-aware culture.

Security Policy Hierarchy

Policies are organized in a hierarchy from most authoritative to advisory:

LevelDescriptionExample
PolicyHigh-level statement of intent; mandatory"All data must be encrypted at rest"
StandardSpecific measurable requirements that implement policy"AES-256 must be used for all data at rest"
ProcedureStep-by-step instructions for implementing a standard"How to enable BitLocker on a Windows workstation"
GuidelineRecommended best practices; advisory, not mandatory"Consider using a password manager"

Key Security Policies

Acceptable Use Policy (AUP): defines what employees may and may not do with company systems. Must be signed by all users. Covers personal use, prohibited activities, monitoring disclosure. Incident Response Policy: defines who does what when an incident occurs; references the IR plan and playbooks. Data Classification Policy: defines classification levels and handling requirements for each level. Password Policy: minimum length, complexity, rotation, reuse restrictions, and lockout settings. BYOD Policy: requirements for personal devices accessing corporate resources (MDM enrollment, acceptable use, remote wipe consent). Clean Desk Policy: sensitive materials must be secured when unattended; reduces risk of shoulder surfing and physical theft.

Due Care vs Due Diligence

Due diligence: researching and understanding risks before making a decision. Example: performing a vendor security assessment before signing a contract. Due care: taking ongoing reasonable action to protect assets. Example: applying security patches, maintaining backups, enforcing the AUP.

Both are required to demonstrate that an organization acted reasonably in protecting assets.

Security Awareness Training

Effective awareness programs:

  • Annual mandatory training for all employees
  • Role-based training for high-risk roles (finance, IT, executives)
  • Phishing simulations with immediate feedback and remedial training for clickers
  • Metrics: track click rates on simulations over time (declining rate = effective training)
  • Foster a "report, don't fear" culture: employees should feel safe reporting suspicious activity
Exam Focus Points
  • Policy hierarchy: Policy (mandatory intent) > Standard (specific requirements) > Procedure (step-by-step) > Guideline (advisory)
  • AUP (Acceptable Use Policy) defines permitted and prohibited use of company systems; must be signed by all users
  • Due diligence = researching risks before acting; due care = ongoing reasonable protective action
  • Phishing simulation click rates measured over time are the primary metric for awareness training effectiveness
  • ISO 27001 is a certifiable ISMS standard; NIST CSF is a voluntary framework (neither replaces the other)
Knowledge Check

1. A company requires that all laptops use AES-256 encryption. This requirement is documented in a written document that all employees must follow. What type of document is this?

2. Before signing a contract with a cloud provider, a CISO reviews the provider's security certifications, penetration test reports, and audit findings. Which concept does this represent?

3. A security team sends simulated phishing emails to employees and tracks who clicks. Users who click receive immediate training. Over 12 months, the click rate drops from 22% to 4%. What does this indicate?

Recommended: Pluralsight

Turn your CompTIA Security+ concepts into passing marks: Pluralsight adds structured study plans, practice exams, and hands-on scenario labs.

Start Security+ prep free10-day free trial available