I am actively using the NIST Cybersecurity Framework and 800 series special publications to define policies and establish security systems within my place of work. While I do recommend actually reading the 800 series, it is extremely dry. Here is a quick guide that "translates" the NIST policy families.
Source: https://www.praxiom.com/nist-cybersecurity-framework.htm
ID. Identify your context
PR. Protect your assets
DE. Detect your anomalies
RS. Respond to incidents
RC. Recover from incidents