Skip to content

The Policy Infokit makes it easy to Find Policies and Standards by searching on topics like data, physical security, patching, development requirements, and more, and includes helpful summaries of key provisions for each, with links to related guidance, controls, and supporting resources.

You can also use this kit to learn more about the stages of the policy and standard Development Process and the roles and responsibilities that support it, look up key terms in the Glossary, or discover where to go if you need an Exception. Just review the Crucial Definitions below and select one of the sections mentioned to get started!

For a list of frequently asked questions about policies and standards, visit our Policies and Standards FAQ, or submit a Policy Action Request for additional policy-related questions or requests.

Refer to Policy Ownership to learn about the process of creating a policy at KP.

Important Notice

This infokit only addresses information privacy and security policies and standards, which are just a portion of the policies and standards published in the KP Policy Library that must be followed. If you work for a KP region you may also be subject to more stringent policies and standards due to state law; contact your manager or local or regional compliance office for more information.

Crucial Definitions

High Level Specific Definition
Policy Standard
  • Communication vehicle describing strategic, high-level guiding principles, roles and responsibilities, and governance.
  • Based on applicable laws, regulations, organizational vision and mission statements, and management direction.
  • Describes “what” is required.
Process
  • Flow of activities, transactions, data, and more through various procedures to achieve a specific result.
Procedure
  • Tactical, detailed guide in alignment with one or more policies and/or standards.
  • Describes “how” an activity is executed, including the use of controls, to achieve intended results. See the Procedure Development Toolkit for more information and help.
Guidance
  • Assists users, systems personnel, and others in understanding and effectively meeting privacy and security compliance requirements.
  • Ensures specific parameters of privacy and security compliance requirements are not overlooked, and highlights alternative methods of meeting those requirements.
Back To Top