Policy A policy defines ‘what’ is to be considered or done in the organisation for cyber security context. Adapted from CISSP, 2014