# Information Security Policy

> Mandatory – ISO/IEC 27001:2022 cl.5.2. The top-level ISMS document:
> sets direction, approved by top management, communicated to staff
> and available to interested parties as appropriate.

| Field | Value |
|-------|-------|
| Document ID | DOC-ISMS-001 |
| Version | N.N |
| Approved by | Top management |
| Effective | YYYY-MM-DD |
| Next review | YYYY-MM-DD |

## 1. Purpose

Establish management's commitment to protecting the confidentiality,
integrity, and availability (CIA) of information.

## 2. Scope

All information assets within the ISMS scope (DOC-ISMS-000):
information in any form, systems, people, processes, facilities.

## 3. Policy statements

### 3.1 Core commitments

1. Information is protected against unauthorized access (C),
   unauthorized modification (I), and loss of availability (A).
2. Security risk is assessed and treated per the risk methodology
   (DOC-ISMS-010).
3. Security objectives are set, measured, and reviewed (cl.6.2).
4. All legal, regulatory, and contractual requirements are met
   (register: DOC-ISMS-014).
5. All staff receive security awareness training; violations lead to
   disciplinary action.
6. Incidents are reported, managed, and learned from (DOC-ISMS-020).

### 3.2 Roles

| Role | Accountability |
|------|----------------|
| Top management | ISMS effectiveness, resources, approval |
| ISMS manager / CISO | day-to-day ISMS operation |
| All staff | comply with policies, report incidents |

## 4. Supporting documents

Subordinate policies implementing this one:

| Doc ID | Topic |
|--------|-------|
| POL-AUP-001 | Acceptable use |
| POL-ACC-002 | Access control |
| POL-INC-003 | Incident response |
| POL-BCP-004 | Business continuity |

## 5. Non-compliance

Consequences of violating this policy.

## 6. Approval & review

Approved by top management; reviewed annually and after significant
change.
