Governance Documents: Policy, Standard, Procedure, and Baseline

Key Takeaways

  • Governance defines who has authority, how decisions are made, and how security aligns with business objectives.
  • Policies state management intent and required outcomes at a high level and are mandatory.
  • Standards define mandatory, measurable requirements that support a policy.
  • Procedures provide step-by-step instructions for repeatable work; guidelines are optional advice.
  • Baselines define the approved minimum secure configuration, and every system must be measured against them.
Last updated: June 2026

Why Governance Is on the Exam

Governance is the structure used to direct, control, and measure a security program. It defines decision authority, accountability, risk appetite, oversight, and alignment with business objectives. On CompTIA Security+ SY0-701 (max 90 questions, 90 minutes, passing 750 on a 100-900 scale, launched November 7, 2023), governance lives in Domain 5.0 "Security Program Management and Oversight," the largest exam domain at roughly 20 percent of scored items. Expect several questions that hand you a scenario and ask which document type is the best fit.

Governance documents form a deliberate hierarchy. Each layer answers a different question and has a different level of authority. Memorize the hierarchy because the wrong layer is the most common distractor.

Document Hierarchy

DocumentAuthorityQuestion it answersExample
PolicyMandatoryWhat outcome does management require?All workforce identities must use multifactor authentication
StandardMandatoryWhat specific, measurable rule enforces the policy?Privileged accounts must use phishing-resistant FIDO2 MFA
ProcedureMandatoryHow exactly do I perform the task?Steps to enroll a user in the approved MFA platform
BaselineMandatoryWhat is the minimum approved configuration?Laptop baseline: full-disk encryption, EDR, 10-min screen lock, central logging
GuidelineOptionalWhat is recommended but not required?Prefer passphrases of 15+ characters

The distinction the exam tests hardest is policy versus standard versus procedure. A policy is durable and rarely changes; it states intent and is approved at the executive or board level. A standard is specific and changes as technology changes (TLS 1.2 today, TLS 1.3 next year) and is typically owned by an engineering or architecture function. A procedure is operational detail maintained by the team that performs the work. A baseline is a configuration snapshot you can audit a machine against, and any drift away from it is a finding.

A useful memory aid: policy = why, standard = what, procedure = how, baseline = the secure starting state. Guidelines are the only optional layer; everything above them is enforceable, and violating a mandatory document can be grounds for corrective action.

Scenario: Remote Access Governance

A company allows remote work but has inconsistent VPN and cloud settings. Leadership approves a remote-access policy; the operational documents then support it.

Governance needBest document
State that remote access must be approved, authenticated, encrypted, and monitoredPolicy
Require MFA, device compliance, 15-minute session timeout, and loggingStandard
Explain how the service desk enrolls a new remote userProcedure
Define approved VPN gateway settings and endpoint posture checksBaseline
Suggest preferred home-network practices for employeesGuideline

Agreements and Specialized Policies

SY0-701 also names specific document types you must recognize by their acronyms. They are heavily tested as "which agreement" questions.

DocumentPurpose
AUP (Acceptable Use Policy)Defines what users may and may not do on company systems
SLA (Service-Level Agreement)Contractual performance/uptime commitments with a provider
MOU/MOA (Memorandum of Understanding/Agreement)Non-binding or binding statement of intent between parties
MSA (Master Service Agreement)Umbrella contract governing future work orders
NDA (Non-Disclosure Agreement)Protects confidential information shared between parties
BPA (Business Partners Agreement)Defines responsibilities and revenue/risk sharing between partners
SOW (Statement of Work)Specific deliverables, timeline, and milestones under an MSA

Ownership and Review

Every governance document needs an owner and a review cycle (commonly annual, or sooner after a major incident, audit finding, regulatory change, or technology shift). A policy with no owner becomes stale; a procedure no one updates produces inconsistent execution and audit failures. Required attributes include the document owner (accountable for accuracy), the approver (showing management authority), the effective date, the review date, the scope (who and what must comply), version history, and a defined exception process.

Without a version and effective date, an auditor cannot prove which requirement was in force at the time of an incident. SY0-701 frames many governance items around this lifecycle: a control that exists on paper but was never reviewed, owned, or measured is treated as ineffective regardless of how good its wording is.

Common Traps

  • Calling every document a "policy" when it is really a standard or procedure.
  • Writing a policy so detailed it becomes a procedure and must change constantly.
  • Creating a baseline but never measuring live systems against it (configuration drift goes undetected).
  • Publishing a standard with no exception process.
  • Confusing an SLA (uptime/performance) with an MOU (intent) or AUP (user behavior).

Exam Focus

If the answer must state executive intent, choose policy. If it must define a specific mandatory technical rule, choose standard. If it must tell someone exactly how to perform a task, choose procedure. If it defines the approved minimum configuration, choose baseline. If it merely recommends, choose guideline. For partner relationships, match the acronym: uptime equals SLA, intent equals MOU, confidentiality equals NDA.

Test Your Knowledge

Which document should state the high-level requirement that all privileged accounts must use approved multifactor authentication?

A
B
C
D
Test Your Knowledge

An auditor wants to compare a laptop's actual settings (disk encryption, EDR, screen-lock timeout) against the approved minimum. Which document defines that minimum?

A
B
C
D
Test Your Knowledge

A cloud provider commits in writing to 99.9 percent monthly uptime with credits for breaches. Which agreement type is this?

A
B
C
D
Test Your KnowledgeMatching

Match each governance document to its best description.

Match each item on the left with the correct item on the right

1
Policy
2
Standard
3
Procedure
4
Baseline