As the name implies, these controls deal majorly with policies and processes. The major controls include:
- Security management policies that deal with risk analysis, risk management, and a policy to review the IT systems themselves
- Workforce security policies dealing with supervision, hiring, clearance, and termination processes of the workforce
- Information access management policies dealing with the authorization of accessing, establishing, and modifying it
- Security awareness training and evaluation policies
- Security incident policies about reporting and responding to the security incident
These policies are under the control of the chief security officer's team.