Split one requirement across the document levels

short · 35 min · Objective 5.1

Task

Take a single security requirement and express it at each level of the document hierarchy (policy, standard, procedure and guideline), name the plan that would call on it, then test the split by changing something and seeing which documents had to change.

Steps

  1. Pick the requirement: remote access to the estate must be authenticated with more than a password.
  2. Write /tmp/policy.md: the intent, why it exists, who it applies to, and that it is mandatory. No product names, no protocol versions, no numbers that will change.
  3. Write /tmp/standard.md: the specifics somebody can audit, such as which factors are acceptable, which are not, and the exception process. Every line should be something a tool or an auditor could check.
  4. Write /tmp/procedure.md: the steps to enrol a user, in an order someone unfamiliar could follow at 3am, including how to verify it worked.
  5. Write /tmp/guideline.md: the advice, such as which method to prefer where there is a choice, and why. Make sure nothing in it is mandatory.
  6. Plans are the fifth kind of document. In /tmp/hierarchy.md, name the plan that would call on your enrolment procedure (for example, the business continuity plan when the MFA provider is unavailable) and say in one sentence why a plan is coordination rather than steps.
  7. Now test the split: SMS is deprecated as an acceptable factor. Which of your documents must change? Record the answer in /tmp/hierarchy.md. If the policy had to change, the specifics were in the wrong document.

Verify

python3 - <<'PY'
import re
pol=open('/tmp/policy.md').read().lower()
std=open('/tmp/standard.md').read().lower()
gui=open('/tmp/guideline.md').read().lower()
specifics=re.compile(r'\b(sms|totp|fido2|rsa|aes|tls ?1\.[0-3]|\d{2,} ?(?:bit|characters))\b')
assert not specifics.search(pol), 'the policy contains a specific that belongs in the standard'
assert specifics.search(std), 'the standard contains no specifics - it is a second policy'
assert re.search(r'\b(must|shall|required)\b', pol), 'the policy is not stated as mandatory'
assert not re.search(r'\b(must|shall|required)\b', gui), 'the guideline uses mandatory language - it is a standard'
print('policy is mandatory and general; standard is specific; guideline is advisory')
PY
grep -ciE "standard|policy unchanged" /tmp/hierarchy.md
grep -ciE "continuity|recovery|incident response plan" /tmp/hierarchy.md

The four assertions are the whole distinction, made checkable. A policy containing a protocol version means every future cryptographic change needs board approval; a guideline using the word "must" is a standard that nobody will audit against because of where it was filed. Both greps must be non-zero: you named the document that changes and the plan that sits above the procedure.

Notes

The test in the last step is the one to carry into the exam. If a change of technology forces the policy to change, the policy was written at the wrong level, and the symptom in real organisations is a policy nobody has updated in years because updating it is too expensive.

This is an independent study companion for CompTIA Security+ SY0-801 and is not produced by or endorsed by CompTIA.