# Information Security Policy

**Organization:** {{COMPANY_LEGAL_NAME}}
**Document owner:** {{POLICY_OWNER_ROLE}}
**Approved by:** {{APPROVER_NAME}}, {{APPROVER_TITLE}}
**Version:** {{VERSION}} · **Effective:** {{EFFECTIVE_DATE}} · **Next review:** {{REVIEW_DATE}}
**Classification:** Internal

---

## 1. Purpose

This policy sets out how {{COMPANY_LEGAL_NAME}} protects the confidentiality, integrity,
and availability of the information and systems it relies on. It defines the principles and
responsibilities that govern our information security program and provides the foundation
for the supporting policies, standards, and procedures referenced herein.

*Mapped to: ISO/IEC 27001:2022 Clause 5.2 (Policy), Annex A 5.1 (Policies for information security).*

## 2. Scope

This policy applies to all employees, contractors, and third parties who access
{{COMPANY_LEGAL_NAME}} information or systems, and to all information assets we own or
process, regardless of format or location.

## 3. Policy statements

### 3.1 Leadership and governance
Management is accountable for information security, commits the resources needed to operate
the program, and reviews its performance at planned intervals.
*A 5.1, Clause 5.1.*

### 3.2 Risk management
We identify, assess, and treat information security risks on a recurring basis and whenever
significant change occurs. Risk decisions are recorded and owned.
*Clauses 6.1, 8.2-8.3.*

### 3.3 Access control
Access to information and systems is granted on a least-privilege, need-to-know basis,
reviewed periodically, and revoked promptly when no longer required. Multi-factor
authentication is required for administrative and remote access.
*A 5.15, A 5.18, A 8.2, A 8.5.*

### 3.4 Asset and data classification
Information assets are inventoried and classified, and are handled according to their
classification throughout their lifecycle.
*A 5.9, A 5.12, A 5.13.*

### 3.5 Human resources security
Personnel are screened where appropriate, agree to their security responsibilities, receive
security awareness training, and are subject to a defined process on role change or exit.
*A 6.1-6.3, A 6.5.*

### 3.6 Operations and change management
Changes to systems are controlled and tested. We maintain logging, monitoring, malware
protection, and timely patching of vulnerabilities.
*A 8.7, A 8.8, A 8.15, A 8.16, A 8.32.*

### 3.7 Supplier and third-party risk
We assess the security of suppliers who handle our information and set security expectations
in agreements before granting access.
*A 5.19-5.22.*

### 3.8 Incident management
Security events are reported through a defined channel, triaged, responded to, and reviewed
so that lessons are captured.
*A 5.24-5.27.*

### 3.9 Business continuity
We plan for the continued availability of critical services during disruption and test those
plans periodically.
*A 5.29-5.30.*

### 3.10 Compliance
We meet applicable legal, regulatory, and contractual obligations relevant to information
security and privacy.
*A 5.31, A 5.34, A 5.36.*

## 4. Roles and responsibilities

| Role | Responsibility |
|---|---|
| Executive sponsor | Accountable for the program; approves this policy |
| Security lead / {{POLICY_OWNER_ROLE}} | Maintains the program and this policy |
| Managers | Enforce the policy within their teams |
| All personnel | Comply; report security events promptly |

*A 5.2 (roles & responsibilities).*

## 5. Compliance and exceptions

Non-compliance may result in disciplinary action. Exceptions require documented risk
acceptance by {{APPROVER_TITLE}} and are time-limited and reviewed.

## 6. Review

This policy is reviewed at least annually and when significant change occurs.
*Clauses 9.3, 10.*

---

*Aligned to ISO/IEC 27001:2022. "ISO" and "ISO/IEC 27001" are referenced as the relevant
standard; {{COMPANY_LEGAL_NAME}} is not affiliated with or endorsed by ISO/IEC. The full
standard text is copyrighted and is not reproduced here.*

