Latching on to TechGrunt's post, please see the NIST 800 series of documents. These are used more often than the rainbow series (TCSEC, TNI, etc.).

I personally base all of my policies off the NIST 800 series.

--TH13