A program policy establishes the authority and direction of the security programme. Review it when objectives, obligations or organisational arrangements change, even if its principles are more stable than technical procedures.

Program policy is used to create an organization’s information security program.

Program policies set the strategic direction for security and assign resources for its implementation within the organization.

An authorised senior management official issues program policy to establish or restructure the organization’s information security program. This high-level policy defines the purpose of the program and its scope within the organization, addresses compliance issues, and assigns responsibility to the information security organization for direct program implementation as well as other related responsibilities.

(Source: NIST SP 800-12 Rev. 1)