What is the difference between a policy, a practice, and a control?
Learn the distinctions security reviewers expect and how to describe your company accurately.
6 min read
The short answer
A policy is what your company says should happen. A practice is what people say they do. A control is a safeguard actually in place. Evidence can support that implementation, testing asks whether the control worked as intended, and independent certification is a separate status.
A policy is the written rule
A policy explains what the company expects or requires. It may be approved and distributed, but the document alone does not prove that the activity is operating.
A practice is what the company says it does
A stated practice describes the current way work is performed. It should be confirmed by someone who knows the process and reviewed when the business changes.
A control is an implemented safeguard
A control is a process or technical measure that is actually in place. Evidence may support that implementation, while testing answers a different question: whether the control worked as intended.
Why the distinction matters
Security questionnaires often mix these concepts. Accurate answers should say whether something is documented, practiced, implemented, evidenced, tested, or independently certified rather than treating those statuses as interchangeable.
Related resources