Skip to content

Information security policy: structure and example outline

3 min read Last checked on

An information security policy is the short document, approved by management, that states why the organisation protects information, what falls within scope, who is responsible for what and which objectives it sets. ISO 27001 requires it in clause 5.2. The detail belongs in underlying procedures, not in the policy itself.

An information security policy is the document in which management states why the organisation protects information and which direction it takes in doing so. It is short, it is approved, and every other document in the ISMS refers back to it. A policy that nobody can act on is a liability, because the auditor reads it and then asks who does what.

What ISO 27001 asks of the policy

ISO 27001 covers the policy in clause 5.2, under leadership. In our own words, the standard asks that the policy:

  • fits the purpose of the organisation;
  • contains information security objectives, or says how they are set;
  • includes a commitment to meet the applicable requirements;
  • includes a commitment to keep improving the ISMS;
  • is documented, communicated within the organisation and, where appropriate, available to interested parties.

In control 5.1, Annex A also asks for topic specific policies where needed, such as access control or suppliers, and for planned moments at which all of those policies are reviewed. The general policy is the frame, the topic specific policies hang from it.

An example outline

An outline an auditor can follow easily:

  1. Purpose. Why the organisation protects information, in one paragraph and in the language of the business.
  2. Scope. Which services, locations and systems it covers, matching the scope of the ISMS.
  3. Principles. The three to five principles every decision is tested against, for example that access is granted based on role.
  4. Objectives. Measurable goals for this year, or a reference to where they are kept and how they are set.
  5. Roles and responsibilities. Who owns the ISMS, who assesses risks, who handles incidents, and what is expected of every employee.
  6. Compliance. The commitment to meet legal, contractual and normative requirements, and what happens when the policy is not followed.
  7. Improvement. The commitment to keep improving the ISMS, and how that happens.
  8. Underlying documents. A list of the topic specific policies and procedures that work this policy out.
  9. Approval and review. Who approved it, on which date, and when it will be assessed again.

What does not belong in it

  • Procedures. What a password looks like or how a backup is tested belongs in underlying documents. Those change more often than the policy.
  • Text from the standard. The policy describes what your organisation does, not what the standard says.
  • Promises you do not keep. Every sentence in the policy is something an auditor can ask evidence for.

Approving, communicating and reviewing

A policy only counts once management has approved it. Record who approved it and when. Then communicate it to everyone bound by it, and keep a record that this happened, for example at onboarding.

Include the policy in the yearly management review. Does it still fit the scope, are the objectives still right, are the roles still assigned correctly? A policy that is reapproved unchanged every year is fine, as long as the review shows those questions were asked.

Frequently asked questions

How long should an information security policy be?

Short enough that the people bound by it actually read it. Two to four pages is common. Detail belongs in underlying procedures and topic specific policies.

Who approves the policy?

Management. ISO 27001 places the policy under leadership. A policy that nobody in management has approved is, to an auditor, a draft.

How often should the policy be reviewed?

At planned intervals, in practice at least once a year during the management review, and whenever the scope, the organisation or the risks change substantially.

Can I copy an example policy?

Copying a structure is fine. Copying a text word for word works poorly, because an auditor checks whether the policy fits your organisation, your scope and your risks.

Read next

Sources

  1. ISO, ISO/IEC 27001 Information security management systems
  2. NEN, information security and standards

Trustbird is being built with two certified design partners, and we are looking for more companies to join them at co-founder pricing.

Become a design partner