# Email and communications security policy

Source: https://aestech.com.au/policy-templates/#email-and-communications-policy
Markdown URL: https://aestech.com.au/policy-templates/email-and-communications-policy.md

Use for ISO 27001 A.5.14 and A.8.24, information transfer, encryption in transit, phishing response, and SOC 2 communication controls.

Frameworks: ISO 27001, SOC 2

Use this as a starting point only. Adapt it to your real scope, systems, legal obligations, customer commitments and operating process.

```text
1. Purpose
This policy defines how company email and other communication channels are used and protected, so that information sent inside and outside the company is transferred securely, phishing is handled consistently, and records are retained appropriately.

2. Scope
This policy applies to all staff and contractors using company email, chat, video conferencing, file sharing and any other channel used to transmit company or customer information.

3. Policy statements
- Company business must be conducted only through approved channels listed in [approved communications register], such as [company email, chat platform, video tool]. Personal accounts must not be used for company business.
- Email in transit must be protected by TLS. Mail to domains that cannot support encrypted transport must not carry Confidential or Restricted information.
- Confidential or Restricted content sent externally must use [message encryption feature, secure file share link, or approved portal] rather than plain attachments. Credentials, keys and card data must never be sent by email or chat.
- Automatic forwarding of company mail to external addresses is prohibited. Manual forwarding of Confidential material outside the company requires a business need and, where required, approval from [role].
- Staff must verify unusual or high-risk requests received by email, such as payment changes or credential requests, through a second channel before acting.
- Suspected phishing must not be replied to, clicked or forwarded to colleagues. It must be reported using [report button or security contact] immediately. Anyone who has clicked a link or entered credentials must report it at once; early reporting is never penalised.
- Distribution lists and external sharing settings must be reviewed before sending bulk or sensitive communications, and recipients checked before sending.

4. Roles and responsibilities
- Staff: use approved channels, apply encryption rules, report phishing.
- [IT or security lead]: maintain mail security controls such as SPF, DKIM, DMARC, filtering and alerting, and run phishing awareness activities.
- Managers: reinforce reporting culture and escalate repeated issues.

5. Procedures
- Reported phishing is triaged by [security contact] within [4 hours]; confirmed campaigns trigger the [incident response policy].
- Requests to send Restricted data externally are raised in [ticketing system] for approval.
- Mailbox retention follows the [retention schedule]; legal holds override deletion when instructed by [role].

6. Evidence and records
Keep phishing reports and triage records, mail security configuration exports, DMARC reports, forwarding rule audit results, external transfer approvals, retention settings and training completion records.

7. Review
Owner: [role]. Reviewed at least annually and after significant phishing incidents or changes to communication platforms.
```

Full template pack: https://aestech.com.au/policy-templates/policy-pack.md