To build a framework for security policies and controls, one can use the following approach: 1) document the concepts and principles you will adopt; 2) apply them to security policies and standards; and 3) develop security controls and procedures.