The headline statements aren't actually in conflict. You'd start from high level governance principles and then work down to policy, standards, baselines, guidance and procedures. The bulleted list is not too helpful in1.6 though 😉
-----------------------------------------------------------
Steve Wilme CISSP-ISSAP, ISSMP MCIIS