The high-level policy of an organization that specifies what information is to be collected or created, and how it is to be managed.
Source(s):
NIST SP 800-152