Use an issue-specific policy when a topic needs clear organisational rules beyond the general security policy. Write for the people expected to apply those rules.
Based on the guidance from the information security policy, issue-specific policies are developed to address areas of current relevance and concern to an organization.
The intent is to provide specific guidance and instructions on proper usage of systems to employees within the organization.
An issue-specific policy addresses a topic that needs explicit direction; a separate policy is not required for every technology. Review these policies regularly and when relevant technology, risks or obligations change. Program policies also require review, although their governing principles may change less frequently.
Example Topics for Issue-Specific Policy:
- Internet Access
- Bring Your Own Device (BYOD)
- Social Media
(Source: NIST SP 800-12 Rev. 1)