Governance Risk Compliance
政策框架
A structured set of overarching policies, standards, and guidelines that governs how information security, compliance, and risk are managed across an organization.
Quick answer: A structured set of overarching policies, standards, and guidelines that governs how information security, compliance, and risk are managed across an organization.
This term page is part of the Protermify Cybersecurity glossary and is published as static HTML for fast indexing and clear language coverage.
Definition
A structured set of overarching policies, standards, and guidelines that governs how information security, compliance, and risk are managed across an organization.
Operational example
The organization's policy framework is aligned with ISO/IEC 27001 and regularly reviewed to address emerging cyber risks.
Localized example
组织的政策框架与ISO/IEC 27001一致,并定期审查以应对新出现的网络风险。
Definition language
English reference definition
Source
ISO 27001, NIST Cybersecurity Framework, MITRE ATT&CK
Exam relevance
- CISSP
- CompTIA Security+
- CEH
Target audience
- SOC Analysts
- Security Engineers
- Incident Responders