Free policy template ISO 27001

Information Security Policy

The top-level policy that anchors your whole program: leadership, risk, access, and the commitments everything else references.

Download the Markdown

Free and ungated, no email required. The full template is below and in the download. Authored in Keel's own words and mapped to ISO 27001 by clause; replace the {{PLACEHOLDER}} tokens with your details.

How to use it

  1. Download the template. Grab the Markdown file, or copy the full text from this page.
  2. Fill in the placeholders. Replace every {{PLACEHOLDER}} token (company name, owner, approver, dates, version) with your details.
  3. Tailor it to how you operate. Adjust the statements so they describe what your organization actually does. A policy you do not follow is worse than none.
  4. Approve and publish. Have an accountable owner approve it, set an effective date and a review date, and share it where staff can find it.
  5. Keep it current. Review on the schedule you set (or when things change), and keep evidence that it is followed. In Keel this is tracked for you.

Related

Information Security Policy

Organization: {{COMPANY_LEGAL_NAME}} Document owner: {{POLICY_OWNER_ROLE}} Approved by: {{APPROVER_NAME}}, {{APPROVER_TITLE}} Version: {{VERSION}} · Effective: {{EFFECTIVE_DATE}} · Next review: {{REVIEW_DATE}} Classification: Internal


1. Purpose

This policy sets out how {{COMPANY_LEGAL_NAME}} protects the confidentiality, integrity, and availability of the information and systems it relies on. It defines the principles and responsibilities that govern our information security program and provides the foundation for the supporting policies, standards, and procedures referenced herein.

Mapped to: ISO/IEC 27001:2022 Clause 5.2 (Policy), Annex A 5.1 (Policies for information security).

2. Scope

This policy applies to all employees, contractors, and third parties who access {{COMPANY_LEGAL_NAME}} information or systems, and to all information assets we own or process, regardless of format or location.

3. Policy statements

3.1 Leadership and governance

Management is accountable for information security, commits the resources needed to operate the program, and reviews its performance at planned intervals. A 5.1, Clause 5.1.

3.2 Risk management

We identify, assess, and treat information security risks on a recurring basis and whenever significant change occurs. Risk decisions are recorded and owned. Clauses 6.1, 8.2-8.3.

3.3 Access control

Access to information and systems is granted on a least-privilege, need-to-know basis, reviewed periodically, and revoked promptly when no longer required. Multi-factor authentication is required for administrative and remote access. A 5.15, A 5.18, A 8.2, A 8.5.

3.4 Asset and data classification

Information assets are inventoried and classified, and are handled according to their classification throughout their lifecycle. A 5.9, A 5.12, A 5.13.

3.5 Human resources security

Personnel are screened where appropriate, agree to their security responsibilities, receive security awareness training, and are subject to a defined process on role change or exit. A 6.1-6.3, A 6.5.

3.6 Operations and change management

Changes to systems are controlled and tested. We maintain logging, monitoring, malware protection, and timely patching of vulnerabilities. A 8.7, A 8.8, A 8.15, A 8.16, A 8.32.

3.7 Supplier and third-party risk

We assess the security of suppliers who handle our information and set security expectations in agreements before granting access. A 5.19-5.22.

3.8 Incident management

Security events are reported through a defined channel, triaged, responded to, and reviewed so that lessons are captured. A 5.24-5.27.

3.9 Business continuity

We plan for the continued availability of critical services during disruption and test those plans periodically. A 5.29-5.30.

3.10 Compliance

We meet applicable legal, regulatory, and contractual obligations relevant to information security and privacy. A 5.31, A 5.34, A 5.36.

4. Roles and responsibilities

Role Responsibility
Executive sponsor Accountable for the program; approves this policy
Security lead / {{POLICY_OWNER_ROLE}} Maintains the program and this policy
Managers Enforce the policy within their teams
All personnel Comply; report security events promptly

A 5.2 (roles & responsibilities).

5. Compliance and exceptions

Non-compliance may result in disciplinary action. Exceptions require documented risk acceptance by {{APPROVER_TITLE}} and are time-limited and reviewed.

6. Review

This policy is reviewed at least annually and when significant change occurs. Clauses 9.3, 10.


Aligned to ISO/IEC 27001:2022. "ISO" and "ISO/IEC 27001" are referenced as the relevant standard; {{COMPANY_LEGAL_NAME}} is not affiliated with or endorsed by ISO/IEC. The full standard text is copyrighted and is not reproduced here.

This template is authored by Keel in its own words. Clause references to ISO 27001 are factual identifiers; Keel is not affiliated with or endorsed by the standards bodies named. It is a starting point, not legal advice, review and adapt it for your organization.

Manage this policy in Keel

Keel ships this template in-product, fills the placeholders, maps it to your controls, and tracks approvals and reviews, so the policy stays live evidence, not a file in a drive. Start free.

Start free Browse all templates