GlossaryCompliance operations

Information security policy

Short answer

An information security policy is the top level document, approved by management, that sets out an organisation's commitment to information security, its objectives, the roles and responsibilities involved and the principles that more detailed policies and procedures must follow.

What it contains

The purpose and scope, the security objectives or the framework for setting them, management's commitment to meet applicable requirements and to continual improvement, the main roles and responsibilities, and how the policy is communicated and reviewed. It is usually short, two to five pages, and written for every employee, not only the IT team.

The policy and the topic specific policies

Beneath the main policy sit topic specific policies: acceptable use, access control, passwords, backup, BYOD, remote working, supplier security, incident response and so on. Then come procedures that describe how each policy is put into practice. Keeping these layers separate makes it easier to update the details without changing what management approved.

Making policies real

A policy only works if people know it and it matches reality. Employees should acknowledge it when they join and after significant changes, its content should appear in security awareness training, and it should be reviewed at least once a year. Auditors compare policies with what actually happens; a well written policy that nobody follows becomes a nonconformity.

Where it shows up in compliance

ISO 27001 requires a policy approved by top management (clause 5.2) and topic specific policies (Annex A 5.1). The ENS requires a security policy approved by the organisation's governing body, and NIS2 and SOC 2 also expect documented, approved policies.

Related terms

Keep reading on this topic

Running security as a repeatable process: policy management, risk registers, evidence upkeep, supplier assessment and audit readiness between cycles.

Go to the topic hub