Security policy
A document approved by leadership that sets the organization's security objectives and responsibilities.
Security regulations
A set of rules that develop the policy for specific matters: equipment use, remote access, mobile devices.
Authorization process
A procedure to authorize system components going into production before they're used.
What an auditor usually asks for
- Security policy approved by leadership
- Security regulations documented and communicated
- Operational security procedures defined
- Component authorization process active
How to cover this block in Kimobox
- 1Document the security policy and regulations as controlled documents.
- 2Log the component authorization process as an approval workflow in Kimobox.
- 3Communicate the regulations to all involved staff from the employee portal.
The security policy and regulations stay version-controlled with evidence they were communicated to the team.
Where each figure comes from
References to the official text in force. If a standard is revised, this page is updated and the review date says so.
- Royal Decree 311/2022 regulating the National Security Framework BOE-A-2022-7191 · 4 May 2022
- National Cryptologic Centre — CCN-STIC guides CCN-CERT · ENS guide series
- Directive (EU) 2022/2555 (NIS2) EUR-Lex · Transposition deadline: 17 October 2024