Policies for information security
Purpose
Keep management direction and support for information security current, suitable and effective and aligned with business, legal and contractual needs.
How to meet this control
In short: Define, approve, publish and communicate information security policies, have relevant staff and interested parties acknowledge them, and review them at planned intervals and after significant changes.
- Step 01Adopt a single approval workflow in your document system (SharePoint, Confluence or a GRC platform) that routes each policy to the CISO and an executive sponsor for sign-off before publication
- Step 02Maintain a policy register that lists every policy, its owner, version number, approval date and next review date so nothing silently goes stale
- Step 03Set a fixed annual review cadence and a trigger-based one (new legislation such as updates to the Privacy Act, major incidents, restructures or new product lines)
- Step 04Publish policies on the intranet and capture electronic acknowledgement at onboarding and at each major revision through your LMS or HR system
- Step 05Cross-reference each topic-specific policy back to the master policy so wording, definitions and classification terms stay consistent
Tip: Keep a top-level policy plus topic-specific ones; version and date each, and record management approval.
What ISO 27002 says to cover
Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.
- ›Define a top-level information security policy approved by senior leadership that sets the overall approach to managing security
- ›Base the policy on business strategy, applicable laws, regulations and contracts, and current and projected security risks and threats
- ›Cover key elements such as a definition of security, objectives, guiding principles, commitments to meet applicable requirements and to improve continually, and allocation of security responsibilities to defined roles
- ›Include a procedure for handling exemptions and exceptions to the policy
- ›Support the high-level policy with topic-specific policies for areas like access control, asset management, backup and incident management, each approved at an appropriate level of management by suitably skilled staff
- ›Communicate policies in a form that is accessible and understandable to the intended readers, and require relevant people to acknowledge and agree to follow them
- ›Review policies at planned intervals and when significant changes occur, feeding in management review and audit results, and have top management approve any changes to the main policy
- ›Keep related policies consistent when one changes, and take care not to expose confidential detail if policies are shared outside the organisation
Audit evidence to keep
- - Approved master information security policy showing version number, approval date and named executive approver
- - Policy register listing all topic-specific policies with owners, review dates and current versions
- - Electronic acknowledgement records showing staff have read and accepted the current policy set
- - Minutes or sign-off recording the most recent management review of the policies
Common mistakes
- - Writing a policy but not operating the process
- - Keeping evidence in personal folders where auditors cannot trace it
- - Letting exceptions stay open with no owner or expiry date
Owner, cadence, and proof
Assign one accountable owner for A.5.1. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.