NIST Policy Template Guides

This article provides links to external sources for policy templates. These resources will support NIST-based frameworks.

Written By Micah

While Strike Graph does have a robust library of audit-proven templates, there are times when you may need a template for a unique purpose. The links below are excellent resources for these one-off situations.

When complying with NIST-based frameworks (such as CMMC or FedRamp), there is no better template than one recommended by NIST.

In addition, the SANS resource has examples of less frequently utilized policy and procedure templates.

The following policies are referenced within Strike Graph, and templates can be found in the links above:

ACCESS CONTROL

AWARENESS AND TRAINING

AUDIT AND ACCOUNTABILITY

SECURITY ASSESSMENT AND AUTHORIZATION

CONFIGURATION MANAGEMENT

CONTINGENCY PLANNING

IDENTIFICATION AND AUTHENTICATION

INCIDENT RESPONSE

MAINTENANCE

MEDIA PROTECTION

PHYSICAL AND ENVIRONMENTAL PROTECTION

PLANNING

PERSONNEL SECURITY

PII PROCESSING AND TRANSPARENCY

RISK ASSESSMENT

SYSTEM AND SERVICES ACQUISITION

SYSTEM AND COMMUNICATIONS PROTECTION

SYSTEM AND INFORMATION INTEGRITY

SUPPLY CHAIN RISK MANAGEMENT FAMILY

Questions?

Reach out through our chat feature for real-time Customer Success support 8 am - 5 pm PT Monday through Friday.