ISO 27001 · the information security policy
The information security policy, written from ten answers
Clause 5.2 asks top management for one short policy, the document an auditor reads first and every other policy sits under: fit for the company's purpose, framing the objectives, committed to the requirements that apply and to continual improvement, and written below from your answers in plain words.
The policy
A short policy is a better one: an auditor reads it for the commitments and the roles, not for length.
# Information security policy: [company] Owner: [the system owner] · Approved by: [top management] · Review: at least annually Written on with the free page on getstandardos.com against Clause 5.2 of ISO/IEC 27001:2022. The wording is StandardOS's own; it is a starting point to approve and communicate, not a final answer. ## Purpose [company] is committed to protecting the confidentiality, integrity and availability of the information it holds and processes to deliver [the product or service], including the personal data of its customers. This policy sets the direction for the information security management system and is the policy every other security policy at [company] sits under. ## Scope This policy applies to all employees and contractors acting on behalf of [company], across its premises and the remote workplaces of its staff, and to every system within the scope of the management system. The scope statement, with what is in and out of it and why, is a document of its own. ## Why it matters to us Our customers make information security a condition of doing business with [company], and this management system is how we show them, and their auditors, that the condition is met. ## Commitments - We identify the information security risks to our business and treat them through a documented risk assessment and treatment process, with acceptance criteria that top management has agreed. - We meet the legal, regulatory and contractual obligations recorded in the context of the management system, data protection law included. - We give every person the awareness and training their role needs, and we hold them to the rules that apply to them. - We measure whether the management system works, audit it ourselves, review it at management level and improve it. - We provide the resources the management system needs to run. ## Objectives This policy provides the framework for setting and reviewing the information security objectives. The current objectives, each measured and reported on at the management review, are: - Keep the service available: uptime measured against the commitment made to customers and reviewed monthly. - Protect customers' information: no confirmed unauthorised disclosure, and every access to production data tied to a named person. - Detect and handle incidents in time: every incident logged, assessed and, where a duty to report applies, reported within its deadline. ## Roles and responsibilities | Role | Who | Responsibility | |---|---|---| | Top management | [top management] | Owns this policy, sets the objectives, provides the resources and reviews the management system at the intervals set below | | System owner | [the system owner] | Runs the management system day to day: the risk register, the Statement of Applicability, the calendar, the internal audit programme and the reporting to top management | | System and asset owners | named per asset in the asset register | Decide who may access their systems and information, and make sure the measures that protect them operate | | Everyone | all staff and contractors | Follow the security rules that apply to their role and report events and weaknesses | ## The policies under this one Topic-specific policies and procedures set the rules in each area: access control, acceptable use, classification and handling, cryptography, backup and recovery, logging and monitoring, secure development, vulnerability and change management, business continuity, physical security, people security, network security, personal data protection, supplier security, incident response. Each is approved by its own approver and reviewed at least annually. Where this policy and a topic-specific policy disagree, this policy prevails and the disagreement is a nonconformity. ## Compliance with this policy Top management requires everyone in scope to follow this policy and the policies under it. Compliance is checked through the internal audit programme and through the reviews each policy sets. A breach is handled under the people security policy and, where it is an incident, under the incident response procedure. ## Communication and availability This policy is published where every employee and contractor can read it, is part of onboarding, and is made available to customers, auditors and other interested parties on request. ## Review This policy is reviewed at least annually at the management review, and whenever the business, its obligations or its risks change materially. Changes are versioned and approved through the document control of the management system. Approved by [top management] on [date]. This policy is written from the answers given. It is not legal or certification advice; the certification body assesses the policy at the audit, and the words on the certificate are its own.
StandardOS writes this policy and the ones under it
The policy is the second document StandardOS writes from your answers, after the scope, with the topic policies it names generated in the same words and versioned; the management review, the internal audit and the awareness records it promises are then dates on the calendar, not intentions.