Advertisement

Guideline

Recommended, non-mandatory practices that help implement policy.

In the policy hierarchy, a guideline is the only advisory tier — recommended practice that helps people implement policy, but where deviation is not itself a violation. That makes guidelines useful for emerging or fast-changing areas where a firm standard would be premature or quickly outdated. Contrast with standards and procedures, which are mandatory.

Advertisement

Related terms

Back to Security Program Management and Oversight

Advertisement