---
title: Policies
description: Learn CMMC policy requirements and best practices. Discover the 18 essential cybersecurity policies needed for compliance and effective implementation.
---

[Skip to content](https://support.futurefeed.co/knowledge-base/hc/en-us/articles/360057630431-policies#main-content)

[![FutureFeed-White-Green-SupportCenter](https://support.futurefeed.co/hs-fs/hubfs/FutureFeed-White-Green-SupportCenter.png?width=400&height=99&name=FutureFeed-White-Green-SupportCenter.png)](https://support.futurefeed.co/?hsLang=en)

- [HawkAI™ Support Home](https://support.futurefeed.co/)
- [Knowledge Base](https://support.futurefeed.co/knowledge-base)
- [Submit Ticket](https://support.futurefeed.co/support-forms)
- [My Tickets](https://support.futurefeed.co/support?status=all&view=my_tickets&offset=0)

Open main navigation

Close main navigation

- [HawkAI™ Support Home](https://support.futurefeed.co/)
- [Knowledge Base](https://support.futurefeed.co/knowledge-base)
- [Submit Ticket](https://support.futurefeed.co/support-forms)
- [My Tickets](https://support.futurefeed.co/support?status=all&view=my_tickets&offset=0)

 FutureFeed's Knowledge Base

- There are no suggestions because the search field is empty.

1. [FutureFeed Support](https://support.futurefeed.co/knowledge-base?hsLang=en)
2. [Manage Compliantly](https://support.futurefeed.co/knowledge-base/manage-compliantly?hsLang=en)
3. [Technology Subway Stop](https://support.futurefeed.co/knowledge-base/manage-compliantly?hsLang=en#technology-subway-stop)

# Policies

## Also called: Rulebook, Guidelines, Policy

### What it is

A **Policy** is the organization’s **official rules and principles for how the organization operates**. Policies: 

- Establish standards and acceptable behavior
- Reduce risk and uncertainty
- Support legal and regulatory compliance
- Provide guidance for decision-making

A policy is **not** a how-to guide. It’s more like the rules of the road. Cybersecurity policies are a critical subset of organizational policies, addressing how information systems, data, and digital assets are protected.

---

### Why policies exists

Because in a real organization, people need clarity and consistency. Policies prevent “everyone doing it their own way.”

Cybersecurity policies are formal rules and guidelines designed to protect the **confidentiality, integrity, and availability (CIA)** of information and systems. They define how users, systems, and third parties should interact with organizational technology and data.

These policies apply to:

- Employees and contractors
- Information systems and networks
- Cloud services and third-party platforms
- Company-owned and personal devices used for work

### What it usually looks like

- Short sections like “Purpose,” “Scope,” “Requirements,” “Roles & Responsibilities”
- Statements like “must,” “required,” “shall”
- Often approved by leadership
- Versioned (because auditors and reality both demand receipts)

### Core Examples of Cybersecurity Policies

- Information Security Policy - the foundational policy that outlines the organization's overall approach to information security. It defines security objectives, roles, responsibilities and governance structures.
- Acceptable Use Policy - Defines how users may or may not use company systems, networks and data to include such things as internet and email usage, prohibited activities and personal use limitations.
- Access Control Policy - Specifies how access to systems and data is granted, managed and revoked. Common principles include least privilege, role based access and multifactor authentication.

### Policy use and enforcement

Read it to understand the rule and link your procedures/processes to it (even if writers forget, your system can connect them later).

Failure to comply with cybersecurity policies may result in:

- Disciplinary action
- Loss of system access
- Legal or contractual consequences

Policies are enforced through technical controls, audits, monitoring, and periodic reviews.

### Common confusion

**Policy vs Procedure:**

- Policy = *what/why*
- Procedure = *how*

The official CMMC definition of Policy is:

***A policy is a high-level statement from an organization’s senior management that documents the requirements for a given activity. It is intended to establish organizational expectations for planning and performing the activity and communicate those expectations to the organization. Senior management should sign policies to show its support of the activity.***

**Policy Listing**

The current CMMC Assessment Guide identifies the following policies as it describes the sorts of documents an assessor may look to review:

1. Access Control Policies
2. Asset Management Policies
3. Audit and Accountability Policy
4. Configuration Management Policy
5. Data Protection Policy
6. Identification and Authentication Policy
7. Information Flow Control Policies
8. Information Security Policies
9. Information Technology Policies
10. Insider Threat Policy
11. Password Policy
12. Privacy and Security Policies
13. Security Assessment and Authorization Policy
14. Security Awareness and Training Policies
15. Security Planning Policy
16. Software Review Policy - In House Development
17. Systems Media Policy
18. User-installed Software Policy

Organizations need not have exactly this list of policies, but should have a set of policies that address these items.  Future versions of FutureFeed will allow tagging of uploaded policies with the above list.

**What makes good policy?**

![project-2021-03-04\_11-03\_AM\_\_2\_.png](https://support.futurefeed.co/hubfs/Knowledge%20Base%20Import/project-2021-03-04_11-03_AM__2_.png)

 General Policy Guidance

**Size (Length)** 

Policies can vary significantly in length, and there are advantages and disadvantages to both short and long policies. Generally, conciseness is advised. The length of a policy can determine how easy it is to find the keywords searched for within the policy, and how easy it is to navigate and read. As a general rule, the shorter the policy, the easier it is for users to retrieve the information they are seeking.

**Policy Text Organization**

If your policy is long and contains multiple sub-sections within the Policy Statement section, strive to organize the material using sub-headings and bulleted lists.

Avoid the use of numbering schemes, if possible. If you are anticipating including an ordered list, consider whether the material is actually a process rather than policy. Supplemental information such as procedures is not included in the Policy Library, but links to such material are encouraged within the "Resources" section (see above).

 

- [CMMC Program - Regulation Guidance](https://support.futurefeed.co/knowledge-base/cmmc-program-regulation-guidance?hsLang=en#main-content)

    - [CMMC Program](https://support.futurefeed.co/knowledge-base/cmmc-program-regulation-guidance?hsLang=en#cmmc-program)
- [Product Information](https://support.futurefeed.co/knowledge-base/product-information?hsLang=en#main-content)

    - [Basic Pricing](https://support.futurefeed.co/knowledge-base/product-information?hsLang=en#basic-pricing)
    - [Advanced and Volume Pricing](https://support.futurefeed.co/knowledge-base/product-information?hsLang=en#advanced-and-volume-pricing)
    - [Features](https://support.futurefeed.co/knowledge-base/product-information?hsLang=en#features)
    - [Additional Details](https://support.futurefeed.co/knowledge-base/product-information?hsLang=en#additional-details)
    - [CMMC Express Pricing](https://support.futurefeed.co/knowledge-base/product-information?hsLang=en#cmmc-express-pricing)
- [How-to's](https://support.futurefeed.co/knowledge-base/how-tos?hsLang=en#main-content)

    - [How-to... Build and Manage Projects in "Your FutureFeed"](https://support.futurefeed.co/knowledge-base/how-tos?hsLang=en#how-to-build-and-manage-projects-in-your-futurefeed)
    - [How-to... Deliverables](https://support.futurefeed.co/knowledge-base/how-tos?hsLang=en#how-to-deliverables)
    - [Other Features](https://support.futurefeed.co/knowledge-base/how-tos?hsLang=en#other-features)
    - [How-to... Manage Tools, Services, and Documentation](https://support.futurefeed.co/knowledge-base/how-tos?hsLang=en#how-to-manage-tools-services-and-documentation)
    - [How To... Onboarding Rocket](https://support.futurefeed.co/knowledge-base/how-tos?hsLang=en#how-to-onboarding-rocket)
    - [How-to... Big Picture](https://support.futurefeed.co/knowledge-base/how-tos?hsLang=en#how-to-big-picture)
    - [How to... Work in the Assess Subway Stop](https://support.futurefeed.co/knowledge-base/how-tos?hsLang=en#how-to-work-in-the-assess-subway-stop)
    - [How-to.... Manage People and Users](https://support.futurefeed.co/knowledge-base/how-tos?hsLang=en#how-to-manage-people-and-users)
    - [How To... Complete the SSP](https://support.futurefeed.co/knowledge-base/how-tos?hsLang=en#how-to-complete-the-ssp)
    - [How to ... Manage a Marketplace Listing](https://support.futurefeed.co/knowledge-base/how-tos?hsLang=en#how-to-manage-a-marketplace-listing)
    - [How To.... Recurring Tasks](https://support.futurefeed.co/knowledge-base/how-tos?hsLang=en#how-to-recurring-tasks)
- [Terminology](https://support.futurefeed.co/knowledge-base/terminology?hsLang=en#main-content)

    - [Glossary](https://support.futurefeed.co/knowledge-base/terminology?hsLang=en#glossary)
- [Getting started](https://support.futurefeed.co/knowledge-base/getting-started?hsLang=en#main-content)

    - [Navigation](https://support.futurefeed.co/knowledge-base/getting-started?hsLang=en#navigation)
    - [Subscription Management](https://support.futurefeed.co/knowledge-base/getting-started?hsLang=en#subscription-management)
    - [Platform Access](https://support.futurefeed.co/knowledge-base/getting-started?hsLang=en#platform-access)
    - [Compliance Standards - Background Information](https://support.futurefeed.co/knowledge-base/getting-started?hsLang=en#compliance-standards-background-information)
- [Manage Compliantly](https://support.futurefeed.co/knowledge-base/manage-compliantly?hsLang=en#main-content)

    - [Technology Subway Stop](https://support.futurefeed.co/knowledge-base/manage-compliantly?hsLang=en#technology-subway-stop)
    - [Company Profile](https://support.futurefeed.co/knowledge-base/manage-compliantly?hsLang=en#company-profile)
    - [Deliverables Subway Stop](https://support.futurefeed.co/knowledge-base/manage-compliantly?hsLang=en#deliverables-subway-stop)
    - [Your FutureFeed Subway Stop](https://support.futurefeed.co/knowledge-base/manage-compliantly?hsLang=en#your-futurefeed-subway-stop)
    - [SSP Subway Stop](https://support.futurefeed.co/knowledge-base/manage-compliantly?hsLang=en#ssp-subway-stop)
- [Webinars and Features](https://support.futurefeed.co/knowledge-base/webinars-and-features?hsLang=en#main-content)

    - [NIST SP 800-171 R3](https://support.futurefeed.co/knowledge-base/webinars-and-features?hsLang=en#nist-sp-800-171-r3)
    - [2023 User Webinars](https://support.futurefeed.co/knowledge-base/webinars-and-features?hsLang=en#2023-user-webinars)
    - [Features](https://support.futurefeed.co/knowledge-base/webinars-and-features?hsLang=en#features)
- [CMMC Program](https://support.futurefeed.co/knowledge-base/cmmc-program?hsLang=en#main-content)

    - [CMMC Program - Regulation Guidance](https://support.futurefeed.co/knowledge-base/cmmc-program?hsLang=en#cmmc-program-regulation-guidance)
- [FutureFeed Support](https://support.futurefeed.co/knowledge-base/futurefeed-support?hsLang=en#main-content)

    - [Product Information](https://support.futurefeed.co/knowledge-base/futurefeed-support?hsLang=en#product-information)
- [Frameworks](https://support.futurefeed.co/knowledge-base/frameworks?hsLang=en)
- [Tools and Services](https://support.futurefeed.co/knowledge-base/tools-and-services?hsLang=en)
- [Hawk AI](https://support.futurefeed.co/knowledge-base/hawk-ai?hsLang=en)
- [CMMC Fundamentals](https://support.futurefeed.co/knowledge-base/cmmc-fundamentals?hsLang=en#main-content)

    - [SPRS & Compliance Reporting](https://support.futurefeed.co/knowledge-base/cmmc-fundamentals?hsLang=en#sprs-compliance-reporting)

[![FutureFeed-White-Green-SupportCenter](https://support.futurefeed.co/hs-fs/hubfs/FutureFeed-White-Green-SupportCenter.png?width=300&height=74&name=FutureFeed-White-Green-SupportCenter.png "FutureFeed-White-Green-SupportCenter")](https://support.futurefeed.co/?hsLang=en)

FutureFeed Footer – Newest

## Footer

[1-844-725-8252](tel:14105605602) [support@futurefeed.co](mailto:support@futurefeed.co)

- [Facebook](http://facebook.com/FutureFeedCompliance/)
- [X (Twitter)](https://x.com/futurefeedco/)
- [LinkedIn](https://www.linkedin.com/company/futurefeed/)

Attain. Maintain. Prove It Anytime.

### Resources

- [15-Min with FutureFeed](https://zoom.us/meeting/register/WKkYTumjR6OOUjNRwZi91A#/registration)
- [User - Schedule a Training](https://futurefeed.co/schedule-training/)
- [Partner - Schedule a Training](https://futurefeed.co/schedule-training/)
- [Download the Everything Book](https://futurefeed.co/cmmc_guide/)

### Legal

- [Terms of service](https://futurefeed.co/terms/)
- [Privacy policy](https://futurefeed.co/privacy/)
- [Security](https://futurefeed.co/security/)
- [Legal](https://futurefeed.co/legal/)

©  FutureFeed.co. All rights reserved.

Disclaimer: The appearance of U.S. Department of Defense (DoD) visual information does not imply or constitute DoD endorsement.