It Security Policy – T

Primary definition

he "documentation of IT security decisions" in an organization. NIST SP 800-12 categorizes IT Security Policy into three basic types: 1) Program Policy--high-level policy used to create an organization's IT security program, define its scope within the organization, assign implementation responsibilities, establish strategic direction, and assign resources for implementation. 2) Issue-Specific Policies--address specific issues of concern to the organization, such as contingency planning, the use of a particular methodology for systems risk management, and implementation of new regulations or law. These policies are likely to require more frequent revision as changes in technology and related factors take place. 3) System-Specific Policies--address individual systems, such as establishing an access control list or in training users as to what system actions are permitted. These policies may vary from system to system within the same organization. In addition, policy may refer to entirely different matters, such as the specific managerial decisions setting an organization's electronic mail (email) policy or fax security policy. (SP 800-35) (NISTIR)

Also known asIT Security Policy · Information Technology Security Policy · Security Policy · ITSP
1 sources cited4 related termsReviewed Aug 10, 2026
The Cyber GlossaryView source

Understand more election terms clearly

Get one important election term explained each week, with authoritative sources, practical context and related definitions.

Free. One useful email each week. Unsubscribe anytime.Learn more about the ESG newsletter →
TCG

he "documentation of IT security decisions" in an organization. NIST SP 800-12 categorizes IT Security Policy into three basic types: 1) Program Policy--high-level policy used to create an organization's IT security program, define its scope within the organization, assign implementation responsibilities, establish strategic direction, and assign resources for implementation. 2) Issue-Specific Policies--address specific issues of concern to the organization, such as contingency planning, the use of a particular methodology for systems risk management, and implementation of new regulations or law. These policies are likely to require more frequent revision as changes in technology and related factors take place. 3) System-Specific Policies--address individual systems, such as establishing an access control list or in training users as to what system actions are permitted. These policies may vary from system to system within the same organization. In addition, policy may refer to entirely different matters, such as the specific managerial decisions setting an organization's electronic mail (email) policy or fax security policy. (SP 800-35) (NISTIR)

The Cyber Glossary · 2024

Cite this term

Permanent URL · stable across revisions
Election Security Glossary. (2026). It Security Policy – T. In Election Security Glossary. Retrieved August 13, 2026, from https://electionsecurityglossary.com/glossary/it-security-policy-t

Sources

1 cited · last checked Aug 10, 2026

01

The Cyber Glossary
The Cyber Glossary

Single-source

View source

Get the weekly election term

Receive one cited, source-backed election explanation in your inbox each week.

Get election terms explained weekly →
Free · Nonpartisan · Unsubscribe anytime.
Continue Research

Keep going from here

Three ways to go deeper on cybersecurity and adjacent terminology.