NIST Policy Template Guides
This article provides links to external sources for policy templates. These resources will support NIST-based frameworks.
Written By Micah
While Strike Graph does have a robust library of audit-proven templates, there are times when you may need a template for a unique purpose. The links below are excellent resources for these one-off situations.
When complying with NIST-based frameworks (such as CMMC or FedRamp), there is no better template than one recommended by NIST.
In addition, the SANS resource has examples of less frequently utilized policy and procedure templates.
The following policies are referenced within Strike Graph, and templates can be found in the links above:
ACCESS CONTROL
AWARENESS AND TRAINING
AUDIT AND ACCOUNTABILITY
SECURITY ASSESSMENT AND AUTHORIZATION
CONFIGURATION MANAGEMENT
CONTINGENCY PLANNING
IDENTIFICATION AND AUTHENTICATION
INCIDENT RESPONSE
MAINTENANCE
MEDIA PROTECTION
PHYSICAL AND ENVIRONMENTAL PROTECTION
PLANNING
PERSONNEL SECURITY
PII PROCESSING AND TRANSPARENCY
RISK ASSESSMENT
SYSTEM AND SERVICES ACQUISITION
SYSTEM AND COMMUNICATIONS PROTECTION
SYSTEM AND INFORMATION INTEGRITY
SUPPLY CHAIN RISK MANAGEMENT FAMILY
Questions?
Reach out through our chat feature for real-time Customer Success support 8 am - 5 pm PT Monday through Friday.