# Policy | Secureframe

> Understand cybersecurity policies, policy types (acceptable use, access control, incident response), and policy requirements for SOC 2, ISO 27001, HIPAA, and CMMC compliance.

canonical: https://secureframe.com/glossary/policy

A policy is a governing document describing what an organization does to ensure security and compliance. It outlines responsibilities and general procedures meant to implement and maintain specific security and compliance controls.

## What is a policy?

A policy is a governing document describing what an organization does to ensure security and compliance. It outlines responsibilities and general procedures meant to implement and maintain specific security and compliance controls. An organization will generally outline specific procedures in separate procedure documents.
