Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
Security Leadership and Management

Building Strong Policies for Ongoing Structure and Security

By Jerry J. Brennan, Lynn Mattice
April 1, 2013

Building Strong Policies for Ongoing Structure and SecurityIn every element of our daily lives there are rules that guide our behavior. These rules come to us in many forms. From the time we are infants, our parents teach us what types of behaviors are acceptable and those that are not. We all remember the dreaded “No” from our mothers or fathers which was usually coupled with a stern look on their face. As we grew up, there were rules at school, and as we learned to drive there were traffic laws we needed to obey. Our world is full of legions of government regulations and laws with which we are expected to comply. We all understand that without rules, regulations and laws to guide behavior, civilization as we know it would cease to exist and we would be cast into a world of utter chaos.

Rules, regulations and laws give us that solid foundation to guide behavior and establish the consequences for failure to comply.  As we entered the working world, things like codes of conduct, policies, procedures and processes were added to our list of things to guide us and to which we were expected to conform.

The outer ring of this graphic identifies key elements of establishing a solid foundation for implementing an Enterprise Risk Management (ERM) based program. This month we are focusing only on the area of establishing policies, procedures and processes.

Our working worlds are filled with complexity, whether you work for a company, an NGO, a non-profit or a governmental entity. Establishing rules of behavior and the consequences for failure to comply are critical to ensuring and maintaining any form of consistency and uniformity of actions across the enterprise. Policies, procedures and processes are necessary tools in defining the day-to-day rules of behavior and the steps that are necessary to get your job done efficiently, effectively and in a consistent manner. 

Some organizations try desperately to create an open and free-wheeling environment in the belief that it will foster creativity and innovation. Somewhere along the way, unless it is a one-person entity, policies, procedures and processes will become necessary. Structure is a critical element to the working environment, just as it is to our everyday lives. Without structure, manufactured products would not be produced in a consistent manner, financial transactions would not be trusted and consistent failures would occur. These compliance failures not only can result in loss of trust in products or services, but can reach a level that breach laws and regulations. Ultimately, compliance failures can result in an erosion of the entity’s reputation and significant liability for not only the entity but also for those responsible.

There are a number of different ways to establish structure within an entity.  We have all seen the proliferation of “Mission and Vision” at the top of the food chain in setting the overall operating philosophy for an entity. Some organizations have a very hierarchical structure, while others expect the individual elements of their organization to establish the ground rules for how to operate in those units. Establishing a set of high level policies that guide behavior and set the general standards across the organization is one of the best ways to lay the ground work for consistency across the entity. In the very hierarchical environment, top level policies are typically followed by procedure manuals for each of the various elements of the organization. This hierarchical approach many times leads to classic stove piping and does little for cross-fertilization of operating philosophies or expectations across the organization.

A more effective, but admittedly more complex, structure to track document change management is embedding compliance or operating requirements directly in each functional area’s operating procedures. For example: one approach is to require Procurement to reference the corporate security manual for guidance on the steps necessary to conduct a due diligence review of a potential supply chain partner. Perhaps a more proficient manner is to embed the steps necessary to conduct due diligence of potential supply chain partners directly in the procurement department manual.

One of the most effective ways to ensure people understand what is expected of them is by creating process flow charts and utilizing yes/no decision trees. The old saying “A picture is worth a thousand words” holds very true in today’s complex world.  

 

This article was previously published in the print magazine as "Establish A Solid Foundation."

KEYWORDS: Chief Security Officer (CSO) policy creation process flow charts security compliance security leadership security silo

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Brennan 2016 200px

Jerry Brennan is co-founder and Chief Executive of the Security Management Resources Group of Companies (www.smrgroup.com), the leading global executive search practice focused exclusively on corporate and information security positions.

Mattice 2016 200px

Lynn Mattice is Managing Director of Mattice & Associates, a top-tier management consulting firm focused primarily at assisting enterprises with ERM, cyber, intelligence, security and information asset protection programs. He can be reached at: matticeandassociates@gmail.com

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Cybersecurity
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Columns
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Opened padlock on computer keyboard

10 Data Breaches to Know About (April 2026)

Laptop with desktop screen showing

Research: Microsoft Edge Loads Stored Passwords in Cleartext

SEC Podcast Header Podcast

Credential Management in High Turnover Environments

Glowing police siren

Security Isn’t a Commodity. Neither Is Off-Duty Law Enforcement

Laptop in darkness

Reframing MFA Bypass: Four Identity Gaps Attackers Exploit

SEC 2026 Benchmark Banner

Events

June 10, 2026

Applying Agentic AI in Security Operations for Faster Decisions & Better Outcomes

Security teams have never had more visibility. We’ll explore how a new decision layer is helping security teams move from detection to decision. Turn alerts into decision-ready context, reducing reliance on manual triage and enabling faster action.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • Building Strong Links in Supply Chain Security

    See More
  • Security team meeting

    Five Top Tips for Building a Strong Security Culture

    See More
  • SEC0818-edu-feat-slide1_900px

    Building a Solid Security Structure as the Foundation Starts to Shake

    See More

Related Products

See More Products
  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • Physical Security and Safety: A Field Guide for the Practitioner

  • 150 things.jpg

    The Handbook for School Safety and Security

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing