IT Policies, Standards and Procedures
In the context of the ISACA Certified in the Governance of Enterprise IT (CGEIT) credential, IT policies, standards and procedures form a hierarchical framework. It translates board-level direction into consistent, measurable operational behavior. Together they are a core enabler of effective gover… In the context of the ISACA Certified in the Governance of Enterprise IT (CGEIT) credential, IT policies, standards and procedures form a hierarchical framework. It translates board-level direction into consistent, measurable operational behavior. Together they are a core enabler of effective governance of enterprise IT (GEIT). They ensure that IT supports enterprise objectives, manages risk and optimizes resources. Policies sit at the top of the hierarchy. They are high-level statements of management intent, direction and expectations, approved by senior leadership or the board. Policies state what must be achieved and why, but not how. Examples include an information security policy, an acceptable use policy and a data privacy policy. Good policies align with enterprise strategy, risk appetite, legal and regulatory requirements, and organizational culture. They should be stable over time, clearly communicated and owned by accountable executives. Standards sit beneath policies. They define mandatory, specific and measurable requirements that support policy compliance. Examples include minimum password length, approved encryption algorithms and technology platform baselines. Standards create consistency, reduce complexity and support interoperability and cost control. They change more often than policies as technology evolves. Procedures are detailed, step-by-step instructions that describe how to carry out tasks in line with standards and policies. Examples include user provisioning steps, change management workflows and backup routines. Procedures are owned by operational managers and updated frequently. Guidelines are sometimes added as non-mandatory recommendations. From a CGEIT perspective, governance bodies must ensure that this framework exists, is aligned with the COBIT governance principles and the enterprise architecture, and is periodically reviewed. Compliance must be monitored through metrics, audits and exception management processes. Clear ownership, version control, communication and training are essential. Effective policy management demonstrates accountability, supports value delivery and strengthens risk management and assurance. It provides stakeholders with confidence that IT is directed and controlled appropriately.
IT Policies, Standards and Procedures: A Complete CGEIT Guide (Governance of Enterprise IT)
Introduction
In the ISACA Certified in the Governance of Enterprise IT (CGEIT) certification, IT Policies, Standards and Procedures sit within Domain 1: Governance of Enterprise IT. They are the practical mechanisms that turn the board's intentions, strategy and risk appetite into consistent, measurable behaviour across the organisation. CGEIT candidates are expected to think like a governance professional, not a technician. That means understanding why these instruments exist, who owns and approves them, how they cascade and are maintained, and how they support value delivery, risk optimisation and resource optimisation.
Why IT Policies, Standards and Procedures Are Important
1. They translate governance into action. The board sets direction (Evaluate, Direct, Monitor in ISO/IEC 38500 and COBIT). Policies are the primary instrument through which direction is communicated. Without them, strategy remains abstract.
2. They establish accountability. Policies define roles, responsibilities and decision rights, so it is clear who is accountable for outcomes.
3. They manage risk within appetite. Policies set boundaries (what is permitted and what is prohibited) aligned with the enterprise risk appetite and tolerance.
4. They support compliance. Laws and regulations (e.g., GDPR, SOX, HIPAA) and contractual obligations are embedded through policies and standards, giving evidence of due care and due diligence.
5. They drive consistency and efficiency. Standards reduce variation, enable interoperability, simplify support and lower cost.
6. They enable monitoring and assurance. Auditors and governance bodies measure compliance against documented requirements. What is not defined cannot be reliably measured.
7. They shape culture. Well-communicated, management-endorsed policies signal the tone at the top and influence ethical, secure behaviour.
What They Are: Definitions and the Policy Hierarchy
The documents form a hierarchy, moving from high-level intent to detailed instruction:
1. Policy
- A high-level statement of management intent, expectations and direction.
- Answers WHAT must be achieved and WHY.
- Mandatory, stable over time, technology-neutral and brief.
- Approved by senior management or the board (or a delegated committee such as an IT steering or strategy committee).
- Examples: Information Security Policy, Acceptable Use Policy, Data Governance Policy, IT Risk Management Policy, Third-Party/Outsourcing Policy.
2. Standards
- Mandatory, specific requirements that support policies. They make policies measurable.
- Define WHAT specifically is required (e.g., minimum password length of 14 characters, approved encryption algorithms, approved hardware/software platforms).
- Often technology-specific and updated more often than policies.
- Approved by management (e.g., CIO/CISO) within the authority granted by policy.
3. Procedures
- Detailed, step-by-step instructions describing HOW to carry out tasks in line with policies and standards.
- Mandatory for the people performing the process.
- Owned by process owners and operational management, and changed most frequently.
- Examples: user provisioning procedure, change management procedure, backup and restore procedure.
4. Guidelines
- Recommendations or best practices that help with implementation.
- Not mandatory. They give flexibility where a standard is not appropriate.
Related concepts:
- Principles: In COBIT, "Principles, Policies and Procedures" is a governance component (formerly an enabler). Principles are the foundational values that guide policy.
- Baselines: Minimum security configurations, often a form of standard.
- Frameworks: COBIT 2019, ISO/IEC 38500, ISO/IEC 27001/27002, ITIL and NIST provide reference content for policy development.
Memory aid: Policy = WHY/WHAT (intent); Standard = WHAT exactly (measurable requirement); Procedure = HOW (steps); Guideline = SHOULD (advice).
How It Works: The Policy Lifecycle
Step 1: Drivers and alignment. Policies derive from enterprise goals, strategy, risk appetite, legal and regulatory requirements, stakeholder needs and the governance framework. Under COBIT's goals cascade, stakeholder needs become enterprise goals, then alignment goals, and policies support the governance and management objectives.
Step 2: Policy framework design. The organisation establishes a policy framework that defines document types and hierarchy, a template, naming conventions, owners, approval authorities, review cycles and an exception process. COBIT objective APO01 (Managed I&T Management Framework) covers establishing and maintaining policies. EDM01 (Ensured Governance Framework Setting and Maintenance) sets the governance direction behind them.
Step 3: Development. The policy owner drafts with input from stakeholders such as business units, legal, HR, risk, compliance, security and audit. Stakeholder involvement improves buy-in and practicality.
Step 4: Approval. Policies are approved at the appropriate governance level. The board or senior management approves high-level policies. Standards and procedures are approved by management under delegated authority. Senior management approval and support are critical success factors.
Step 5: Communication and awareness. Policies must be published, accessible, communicated and understood. This includes training, awareness programmes and acknowledgement or attestation by staff.
Step 6: Implementation and enforcement. Standards and procedures operationalise the policy. Controls are designed and implemented. Non-compliance has defined consequences, often through HR disciplinary processes.
Step 7: Exception management. A formal process allows documented, risk-assessed, time-bound and approved exceptions. Risk acceptance must be made by someone with appropriate authority, typically the business or risk owner, not IT alone.
Step 8: Monitoring, measurement and assurance. Compliance is tracked through metrics, KPIs/KRIs, self-assessments, internal audit and independent assurance. Results are reported to governance bodies.
Step 9: Review and update. Policies are reviewed periodically (commonly annually) and when triggered by events. Triggers include changes in strategy, regulation, technology, risk profile, mergers and acquisitions, or significant incidents.
Key Governance Roles
- Board of Directors: Sets direction, approves key policies such as risk appetite and governance policies, and oversees compliance.
- IT Strategy Committee (board level): Advises the board on IT strategic direction and policy.
- Executive Management / CEO: Ensures policies are implemented and resourced. Sets the tone at the top.
- IT Steering Committee (executive level): Prioritises investments and oversees implementation.
- CIO / CISO / CRO: Owners of IT, security and risk policies and standards.
- Process Owners: Own and maintain procedures.
- Internal Audit: Provides independent assurance on policy adequacy and compliance. Audit should not own or write the policies, because that would impair independence.
- All Employees and Third Parties: Comply and acknowledge.
Characteristics of Effective Policies
- Aligned with business strategy and risk appetite
- Endorsed by senior management
- Clear, concise, unambiguous and understandable
- Owned, with defined accountability
- Realistic and enforceable
- Communicated and accessible
- Measurable through supporting standards and metrics
- Regularly reviewed and version controlled
- Consistent with one another (no conflicts) and with laws and regulations
- Supported by an exception process
Common Problems Seen in Exam Scenarios
- Policies exist but are not enforced or communicated, so staff are unaware of them.
- Policies are written by IT without business input and are not aligned with business objectives.
- Policies are outdated after a merger, a new regulation or a cloud adoption.
- Business units adopt shadow IT that bypasses standards.
- Too many conflicting policies exist across subsidiaries.
- Policies are too technical or too detailed. A policy that contains procedure-level detail is a design flaw.
- Policies lack ownership or senior management sponsorship.
Policies in Global and Federated Enterprises
Large enterprises often use a global policy with local standards or procedures. The enterprise-wide policy sets minimum mandatory requirements. Local units may add stricter requirements to meet local laws, but may not weaken the global baseline. Where local law conflicts with corporate policy, legal compliance generally takes precedence. The conflict should be escalated and documented through the exception process.
Exam Tips: Answering Questions on IT Policies, Standards and Procedures
Tip 1: Think governance first, not technology. CGEIT answers favour board and management-level actions such as alignment, accountability, oversight and value. If one option is a technical fix and another addresses governance (direction, ownership, alignment), the governance option is usually correct.
Tip 2: Know the hierarchy cold. If a question asks which document is high-level, stable and states management intent, the answer is a policy. If it is mandatory and specific/measurable, it is a standard. If it is step-by-step, it is a procedure. If it is optional or advisory, it is a guideline.
Tip 3: Alignment with business strategy is the top priority. When asked about the MOST important consideration when developing IT policies, look for answers about alignment with enterprise objectives, strategy or risk appetite. Avoid answers about industry best practice alone or technical feasibility.
Tip 4: Senior management support is the critical success factor. For questions on the success of policy implementation, approval and endorsement by senior management or the board is usually the best answer.
Tip 5: Look for the root cause. If policies are not followed, ask why. The best first step is often to determine the cause, such as lack of awareness, impractical policy or no enforcement. Rewriting the policy or disciplining staff immediately is rarely the first step.
Tip 6: Policy before procedure. In sequencing questions, the order is strategy/principles, then policy, then standards, then procedures. Developing procedures before the policy is approved is a trap.
Tip 7: Risk acceptance belongs to the business. In exception questions, the correct approver is the risk owner or business owner with appropriate authority, through a formal, documented, time-bound process. IT should not unilaterally accept business risk.
Tip 8: Internal audit assures; it does not design. Answers in which audit writes or owns policies are generally wrong because they compromise independence. Audit evaluates adequacy and compliance.
Tip 9: Trigger events mean policy review. When the scenario describes a merger, new regulation, new technology (cloud, AI), outsourcing or a major incident, the best answer often involves reviewing and updating policies to keep them aligned.
Tip 10: Prefer enterprise-wide, consistent frameworks. In decentralised scenarios, favour a common policy framework with local adaptation over fragmented, unit-by-unit policies.
Tip 11: Watch qualifier words. Pay close attention to words such as FIRST, BEST, MOST important, PRIMARY. Several options may be valid, but only one fits the qualifier. "FIRST" usually points to assessment or understanding. "MOST important" usually points to alignment or senior management commitment.
Tip 12: Measurability enables monitoring. If asked how to ensure policy compliance can be evaluated, choose answers that involve defined standards, metrics, KPIs and regular reporting to governance bodies.
Tip 13: Policies should be technology-neutral. An option that puts specific vendor products or configuration settings into a policy is a red flag. That level of detail belongs in standards or procedures.
Tip 14: Communication and acknowledgement matter. Policies that are unknown are ineffective. Awareness training and staff attestation are strong supporting answers when the issue is non-compliance caused by ignorance.
Sample Question Walkthrough
Question: An enterprise has recently adopted cloud services across several business units. Internal audit finds that each unit applies different security controls. What should the IT governance function do FIRST?
A. Mandate a single cloud provider
B. Review and update the enterprise IT policy framework to address cloud use, aligned with risk appetite
C. Instruct each unit to write its own cloud procedures
D. Implement a technical cloud access security broker
Answer: B. It addresses the governance gap at policy level, ensures alignment and provides the basis for consistent standards and procedures. A and D are tactical and technical. C perpetuates fragmentation.
Quick Revision Summary
- Policies = management intent; approved at senior level; stable; technology-neutral.
- Standards = mandatory, specific, measurable requirements.
- Procedures = mandatory, step-by-step instructions owned by process owners.
- Guidelines = optional advice.
- The lifecycle runs: align, design, develop, approve, communicate, implement, handle exceptions, monitor, review.
- Relevant COBIT objectives: EDM01 and APO01. Principles, Policies and Procedures is a COBIT governance component.
- Critical success factors are alignment with strategy and risk appetite, plus senior management support.
- In the exam, choose the governance-oriented, root-cause, business-aligned answer.
Unlock Premium Access
Certified in the Governance of Enterprise IT
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2995 Superior-grade Certified in the Governance of Enterprise IT practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CGEIT: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!