Information Security Policy
Organization: {{COMPANY_LEGAL_NAME}} Document owner: {{POLICY_OWNER_ROLE}} Approved by: {{APPROVER_NAME}}, {{APPROVER_TITLE}} Version: {{VERSION}} · Effective: {{EFFECTIVE_DATE}} · Next review: {{REVIEW_DATE}} Classification: Internal
1. Purpose
This policy sets out how {{COMPANY_LEGAL_NAME}} protects the confidentiality, integrity, and availability of the information and systems it relies on. It defines the principles and responsibilities that govern our information security program and provides the foundation for the supporting policies, standards, and procedures referenced herein.
Mapped to: ISO/IEC 27001:2022 Clause 5.2 (Policy), Annex A 5.1 (Policies for information security).
2. Scope
This policy applies to all employees, contractors, and third parties who access {{COMPANY_LEGAL_NAME}} information or systems, and to all information assets we own or process, regardless of format or location.
3. Policy statements
3.1 Leadership and governance
Management is accountable for information security, commits the resources needed to operate the program, and reviews its performance at planned intervals. A 5.1, Clause 5.1.
3.2 Risk management
We identify, assess, and treat information security risks on a recurring basis and whenever significant change occurs. Risk decisions are recorded and owned. Clauses 6.1, 8.2-8.3.
3.3 Access control
Access to information and systems is granted on a least-privilege, need-to-know basis, reviewed periodically, and revoked promptly when no longer required. Multi-factor authentication is required for administrative and remote access. A 5.15, A 5.18, A 8.2, A 8.5.
3.4 Asset and data classification
Information assets are inventoried and classified, and are handled according to their classification throughout their lifecycle. A 5.9, A 5.12, A 5.13.
3.5 Human resources security
Personnel are screened where appropriate, agree to their security responsibilities, receive security awareness training, and are subject to a defined process on role change or exit. A 6.1-6.3, A 6.5.
3.6 Operations and change management
Changes to systems are controlled and tested. We maintain logging, monitoring, malware protection, and timely patching of vulnerabilities. A 8.7, A 8.8, A 8.15, A 8.16, A 8.32.
3.7 Supplier and third-party risk
We assess the security of suppliers who handle our information and set security expectations in agreements before granting access. A 5.19-5.22.
3.8 Incident management
Security events are reported through a defined channel, triaged, responded to, and reviewed so that lessons are captured. A 5.24-5.27.
3.9 Business continuity
We plan for the continued availability of critical services during disruption and test those plans periodically. A 5.29-5.30.
3.10 Compliance
We meet applicable legal, regulatory, and contractual obligations relevant to information security and privacy. A 5.31, A 5.34, A 5.36.
4. Roles and responsibilities
| Role | Responsibility |
|---|---|
| Executive sponsor | Accountable for the program; approves this policy |
| Security lead / {{POLICY_OWNER_ROLE}} | Maintains the program and this policy |
| Managers | Enforce the policy within their teams |
| All personnel | Comply; report security events promptly |
A 5.2 (roles & responsibilities).
5. Compliance and exceptions
Non-compliance may result in disciplinary action. Exceptions require documented risk acceptance by {{APPROVER_TITLE}} and are time-limited and reviewed.
6. Review
This policy is reviewed at least annually and when significant change occurs. Clauses 9.3, 10.
Aligned to ISO/IEC 27001:2022. "ISO" and "ISO/IEC 27001" are referenced as the relevant standard; {{COMPANY_LEGAL_NAME}} is not affiliated with or endorsed by ISO/IEC. The full standard text is copyrighted and is not reproduced here.