For Electronic Information System Policies (EISP), the policies are:
- Acceptable Use Policy from the University of California, Berkeley
- Password Policy from the National Institute of Standards and Technology (NIST)
- Data Classification Policy from the U.S. Department of Defense (DoD)
- Data Backup Policy from the U.S. Small Business Administration (SBA)
- Social Media Policy from the U.S. Department of State
For Information System Security Policies (ISSP) the policies are:
- Access Control Policy from the U.S. Department of Energy (DOE)
- Network Security Policy from the U.S. Department of Homeland Security (DHS)
- Incident Response Policy from the SANS Institute
- Change Management Policy from Microsoft
- Physical Security Policy from the PCI Security Standards Council
Therefore, the above policies addresses specific aspects of information security. Note that the EISPs focus on the use and management of electronic information systems, while the ISSPs focus on the total security of the organization's information systems.