GRM-06: Policy
Control Family:
CSF v1.1 References:
PF v1.0 References:
Control is withdrawn in the next version of this control set and incorporated into: A&A-01: Audit and Assurance Policy and Procedures, BCR-01: Business Continuity Management Policy and Procedures, CCC-01: Change Management Policy and Procedures, CEK-01: Encryption and Key Management Policy and Procedures, DCS-01: Off-Site Equipment Disposal Policy and Procedures, DCS-02: Off-Site Transfer Authorization Policy and Procedures, DCS-03: Secure Area Policy and Procedures, DCS-04: Secure Media Transportation Policy and Procedures, DSP-01: Security and Privacy Policy and Procedures, GRC-01: Governance Program Policy and Procedures, HRS-01: Background Screening Policy and Procedures, HRS-02: Acceptable Use of Technology Policy and Procedures, HRS-03: Clean Desk Policy and Procedures, HRS-04: Remote and Home Working Policy and Procedures, IAM-01: Identity and Access Management Policy and Procedures, IAM-02: Strong Password Policy and Procedures, IPY-01: Interoperability and Portability Policy and Procedures, IVS-01: Infrastructure and Virtualization Security Policy and Procedures, LOG-01: Logging and Monitoring Policy and Procedures, SEF-01: Security Incident Management Policy and Procedures, SEF-02: Service Management Policy and Procedures, TVM-01: Threat and Vulnerability Management Policy and Procedures, TVM-02: Malware Protection Policy and Procedures, UEM-01: Endpoint Devices Policy and Procedures.
Control Statement
Information security policies and procedures shall be established and made readily available for review by all impacted personnel and external business relationships. Information security policies must be authorized by the organization’s business leadership (or other accountable business role or function) and supported by a strategic business plan and an information security management program inclusive of defined information security roles and responsibilities for business leadership.
[csf.tools Note: For more information on the Cloud Controls Matrix, visit the CSA Cloud Controls Matrix Homepage.]
Cloud Control Matrix is Copyright 2023 Cloud Security Alliance.