Cyberlium

GRC › Module 6 › Lesson 3

BeginnerModule 6Lesson 3/5

Policy vs Control

Policy vs control literacy — policy statement, implementing control, evidence stub, owner, review cadence — distinction rows on YOUR `$GRC_LAB` policy-control matrix.

15 min+40 XP3 quiz
Module progress3 of 5

Visual · t37_policy_vs_control

Policy vs control = named distinction rows. $GRC_LAB. Original Cyberlium.

Opening

Policy says what; control proves how — name policy-control mapping rows on YOUR lab matrix before stamping forged policies as audit evidence.

Policy vs control literacy names: policy statement row category, implementing control ID category, evidence artifact stub category, control owner category, and review cadence category. Analyst documents policy-control matrix on `$GRC_LAB` fictional org — three policy rows each linked to control and evidence stub labeled LAB — without backdating policies to fake audit windows, without policy-only compliance claims without controls, without forging signed policy PDFs. Cyberlium teaches governance distinction on YOUR notes. Refused: forged policy artifacts, policy-without-control theater, stranger org policy theft. Lab row: policy-control matrix (three policies, control link, evidence stub, LAB label).

1. Named distinction rows

Policy statement, control ID, evidence stub, owner, review cadence — five literacy anchors.

Each policy links Module 6-1 family control — same catalog thread.

Command guide

Try these commands — Named distinction rows

═══ TOOLS & WEBSITES ═══ Browse / read these (authorized learning only — stay in YOUR lab / program scope)

ISO 27001 — https://www.iso.org/isoiec-27001-information-security.html ISACA — https://www.isaca.org/resources/glossary CIS Controls — https://www.cisecurity.org/controls

═══ INSTALL ═══

Linux (Debian/Ubuntu):

Command — copy this

sudo apt install python3

macOS:

Command — copy this

brew install python3

Windows: Download https://python.org/downloads/

═══ LINUX / macOS ═══

Command — copy this

export GRC_LAB=${GRC_LAB:-$HOME/cyberlium-lab/t37-grc}
cat > "$GRC_LAB/notes/policy-vs-control.md" <<'EOF'
# Policy vs Control vs Procedure — LAB-ORG-001 literacy
## Policy (what & why)
- Example: Access Control Policy — requires least privilege
- Board/CISO approved; reviewed annually
## Standard / Baseline ( measurable expectation )
- Example: MFA required for all privileged accounts
## Procedure (how)
- Example: joiner/mover/leaver access provisioning steps
## Control (testable safeguard)
- Example: IdP enforces MFA; quarterly access review ticket
## Evidence
- Policy PDF + IdP config export + review sign-off (LAB SAMPLE in evidence/)
Gap: policy exists but control not implemented = audit finding literacy
EOF

Command — copy this

grep -E 'Policy|Control|Evidence|Gap' "$GRC_LAB/notes/policy-vs-control.md"
python3 -c "print('Policy states intent; control is testable implementation')"

Primary tools to practice this lesson: grep, python3. Reference sites: ISO 27001 (https://www.iso.org/isoiec-27001-information-security.html); ISACA (https://www.isaca.org/resources/glossary); CIS Controls (https://www.cisecurity.org/controls). Run every command in the box — install first, then the usage lines — only on YOUR lab / program scope.

2. Evidence discipline

Evidence stub labeled LAB — not production stranger org screenshots.

Policy alone does not equal implemented control — document honestly.

3. Refused

No forged signed policies; no policy-only audit pass claims; no backdated artifacts.

Distinction literacy supports honest mapping — not compliance fraud.

4. What you ship: policy-control matrix

Three policy rows + control link + evidence stub LAB + NEVER forged policy line.

5. What you record before the next lesson

Policy-control matrix path.

6. Wrong vs right: fraudulent certs vs YOUR lab templates

Worked failure — same MSF word, opposite target. Right never needs a café Wi-Fi or classmate laptop.

  • Wrong

    Backdate `$GRC_LAB` policy PDF to fake six-month audit window for certification fraud.

  • Right

    Policy-control matrix from `$GRC_LAB` template. Next: Mapping Lab.

Mission: policy-control matrix

1) Name five policy vs control rows. 2) Three policies linked to control IDs. 3) Evidence stub labeled LAB each. 4) Write NEVER forged policy artifact line.

Stuck? Ask Cyberlium AI Mentor

Ask Mentor: “Review cadence — minimum literacy stub?”

Knowledge Check

1

APPLY: Policy vs control literacy uses:

Multiple choice

Knowledge Check

2

APPLY: True or False: Policy document alone proves control implementation.

True or False

Knowledge Check

3

APPLY: Policy-control matrix includes:

Multiple choice

← Previous

Answer all 3 knowledge checks to continue. (0/3 answered)