What policies are required for ISO 27001?
ISO 27001 requires a top-level information security policy, plus supporting policies driven by your risk assessment and Statement of Applicability, commonly covering access control, acceptable use, cryptography, supplier/vendor security, incident management, business continuity, secure development, HR security, and data classification and handling.
One required policy, many supporting ones
ISO 27001 explicitly requires a top-level information security policy approved by leadership. Beyond that, the policies you need are the ones your risk assessment and Statement of Applicability say apply, not a fixed checklist.
Commonly needed policies
Access control; acceptable use; cryptography/encryption; supplier and vendor security; incident management; business continuity; secure development; human-resource security (screening, onboarding, offboarding); and data classification and handling.
Keep policies tied to controls
Policies are only useful if they map to real controls and evidence. Keel provides framework-mapped policy templates and an AI drafter, so each policy links to the controls it supports and the evidence that proves it operates.
FAQ
Is there a fixed list of ISO 27001 policies?
No. Only the top-level information security policy is explicitly required. The rest follow from your risk assessment and Statement of Applicability, so two organizations can legitimately have different policy sets.
Can I reuse SOC 2 policies for ISO 27001?
Largely yes. The underlying controls overlap heavily, so well-written policies can support both with minor adjustments.
Get audit-ready with Keel
The AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.
Start free