Advisory Policy: A type of policy that provides strategic guidance on actions to be taken to achieve certain objectives, often within the context of security best practices. Unlike mandatory policies that dictate specific requirements, advisory policies typically offer recommendations and guidance for improving security. They can cover a wide range of topics, from password complexity and user behavior to disaster recovery strategies and incident response procedures.
Categories: CC D5: Security Operations | CCSP D6: Legal - Risk and Compliance | CISM D3: Information Security Program | CISSP D1: Security and Risk Management | Security+ D5: Security Program Management and Oversight | SSCP D1: Security Concepts and Practices
« Back to Glossary Index