GRC › Module 6 › Lesson 3
Policy vs Control
Policy vs control literacy — policy statement, implementing control, evidence stub, owner, review cadence — distinction rows on YOUR `$GRC_LAB` policy-control matrix.
Visual · t37_policy_vs_control
Policy vs control = named distinction rows. $GRC_LAB. Original Cyberlium.
Opening
Policy says what; control proves how — name policy-control mapping rows on YOUR lab matrix before stamping forged policies as audit evidence.
Policy vs control literacy names: policy statement row category, implementing control ID category, evidence artifact stub category, control owner category, and review cadence category. Analyst documents policy-control matrix on `$GRC_LAB` fictional org — three policy rows each linked to control and evidence stub labeled LAB — without backdating policies to fake audit windows, without policy-only compliance claims without controls, without forging signed policy PDFs. Cyberlium teaches governance distinction on YOUR notes. Refused: forged policy artifacts, policy-without-control theater, stranger org policy theft. Lab row: policy-control matrix (three policies, control link, evidence stub, LAB label).
1. Named distinction rows
Policy statement, control ID, evidence stub, owner, review cadence — five literacy anchors.
Each policy links Module 6-1 family control — same catalog thread.
Command guide
Try these commands — Named distinction rows
═══ TOOLS & WEBSITES ═══ Browse / read these (authorized learning only — stay in YOUR lab / program scope)
ISO 27001 — https://www.iso.org/isoiec-27001-information-security.html ISACA — https://www.isaca.org/resources/glossary CIS Controls — https://www.cisecurity.org/controls
═══ INSTALL ═══
Linux (Debian/Ubuntu):
Command — copy this
sudo apt install python3
macOS:
Command — copy this
brew install python3
Windows: Download https://python.org/downloads/
═══ LINUX / macOS ═══
Command — copy this
export GRC_LAB=${GRC_LAB:-$HOME/cyberlium-lab/t37-grc}
cat > "$GRC_LAB/notes/policy-vs-control.md" <<'EOF'
# Policy vs Control vs Procedure — LAB-ORG-001 literacy
## Policy (what & why)
- Example: Access Control Policy — requires least privilege
- Board/CISO approved; reviewed annually
## Standard / Baseline ( measurable expectation )
- Example: MFA required for all privileged accounts
## Procedure (how)
- Example: joiner/mover/leaver access provisioning steps
## Control (testable safeguard)
- Example: IdP enforces MFA; quarterly access review ticket
## Evidence
- Policy PDF + IdP config export + review sign-off (LAB SAMPLE in evidence/)
Gap: policy exists but control not implemented = audit finding literacy
EOFCommand — copy this
grep -E 'Policy|Control|Evidence|Gap' "$GRC_LAB/notes/policy-vs-control.md"
python3 -c "print('Policy states intent; control is testable implementation')"Primary tools to practice this lesson: grep, python3. Reference sites: ISO 27001 (https://www.iso.org/isoiec-27001-information-security.html); ISACA (https://www.isaca.org/resources/glossary); CIS Controls (https://www.cisecurity.org/controls). Run every command in the box — install first, then the usage lines — only on YOUR lab / program scope.
2. Evidence discipline
Evidence stub labeled LAB — not production stranger org screenshots.
Policy alone does not equal implemented control — document honestly.
3. Refused
No forged signed policies; no policy-only audit pass claims; no backdated artifacts.
Distinction literacy supports honest mapping — not compliance fraud.
4. What you ship: policy-control matrix
Three policy rows + control link + evidence stub LAB + NEVER forged policy line.
5. What you record before the next lesson
Policy-control matrix path.
6. Wrong vs right: fraudulent certs vs YOUR lab templates
Worked failure — same MSF word, opposite target. Right never needs a café Wi-Fi or classmate laptop.
Wrong
Backdate `$GRC_LAB` policy PDF to fake six-month audit window for certification fraud.
Right
Policy-control matrix from `$GRC_LAB` template. Next: Mapping Lab.
Mission: policy-control matrix
1) Name five policy vs control rows. 2) Three policies linked to control IDs. 3) Evidence stub labeled LAB each. 4) Write NEVER forged policy artifact line.
Stuck? Ask Cyberlium AI Mentor
Ask Mentor: “Review cadence — minimum literacy stub?”
Knowledge Check
APPLY: Policy vs control literacy uses:
Multiple choice
Knowledge Check
APPLY: True or False: Policy document alone proves control implementation.
True or False
Knowledge Check
APPLY: Policy-control matrix includes:
Multiple choice