Control
Internal communicationExternal communicationGroup membershipFederationFile exchangeCommunication boundariesRestricted usersPolicy-based access
Policy dimensions
Identity and roleGroup and organizationDevice postureThreat stateCommunication typeGeography where configuredCompliance requirementDeployment environment
Accountability
Administrative changesPolicy changesAccess changesUser provisioningSecurity eventsConfiguration activityCompliance actions
Security policy should follow the risk—not force every population into the same model.
