Security Policy
A security policy is a documented set of rules and guidelines that defines how an organization protects its information, systems, and assets.
“A high-level document describing the principles, approach and major objectives of the organization regarding security.”
(Definition reproduced from the ISTQB Glossary. Copyright belongs to ISTQB.)
View the complete ISTQB GlossaryWhat is Security Policy?
It establishes security objectives, responsibilities, acceptable behaviors, and required controls for employees and stakeholders.
Governance document: Defines organizational security expectations.
Responsibility assignment: Clarifies security roles and obligations.
Foundation: Procedures and controls are derived from the policy.
Real World Example
An online banking login flow is being reviewed after fraud analysts report repeated attempts to discover valid customer accounts.
The concern is not whether ordinary login works; it is how the system behaves when someone intentionally misuses it. Security policy points testing toward that hostile or risky behavior.
The tester probes rate limits, error messages, audit events, lockout behavior, and monitoring signals to see whether the system gives attackers useful feedback.
The team strengthens the controls because Security policy helps them test the product from the perspective of misuse, not only normal customer journeys.
Practice Questions
Question 1
Which statement BEST describes Security policy in the context of ISTQB terminology?
Question 2
A tester needs to explain Security policy to a non‑technical stakeholder. Which approach is MOST appropriate?
Test your knowledge with real ISTQB-style questions
You’ve learned Security Policy. Test your understanding with topic-specific questions in our Mock Exams.