A good place to drown in information?
Infosyssec.net/ is at first glance overwhelming, but has some really nice corners, e.g. on
Standards and Regulations , ... An other nice place to find more of these is
http://www.diffuse.org/secure.html
- And finally
ISM Ant's Security Matters gives a nice view on what "governance", "policies", "standards" and "guidelines" might be. (incl. seasoned links)