Security Policy Now Critical
Regulators put it on par with power grids, requiring continuous monitoring to prevent harm to customers and markets

A security policy is now considered critical infrastructure, as its failure can cause significant harm to customers, markets, or public safety. This classification puts security policy on par with essential systems such as payment platforms in clearing banks and SCADA networks in power distributors.
The policy environment, which determines how different systems interact with each other, is a complex set of rules that govern access decisions across various enforcement points. A misconfigured rule can have severe consequences, such as severing a payment service from its settlement platform.
Regulated organizations are expected to manage their policy environments with the highest governance obligations, including continuous monitoring and validated change control. However, many organizations still treat policy management as an operational task, adding rules through change requests without regularly examining the accumulated result against the intended outcome.
The failure of a security policy can have significant consequences, including the disruption of important business services. For example, a policy failure that severs connectivity between settlement systems would be considered a disruption of an important business service, and regulators such as the FCA would take an interest in such incidents.
## Why it matters The classification of security policy as critical infrastructure highlights the importance of effective policy management in preventing harm to customers and markets. As regulated organizations continue to rely on complex systems and networks, the need for robust security policies and governance obligations will only continue to grow. The consequences of policy failure can be severe, and organizations must prioritize policy management to ensure the continuity of critical services.
The fact that many regulated organizations still manage their policy environments as operational tasks is a concern, as it can lead to misconfigured rules and unintended consequences. By recognizing the critical importance of security policy, organizations can take steps to improve their policy management practices and reduce the risk of policy failure.





