A formal set of statements that define the goals, requirements, and constraints of an organization’s security program, focusing on what must be protected and why, rather than how controls are implemented.
« Back to Glossary Index « Back to Glossary Index
