Information Security Policy
ISMS policy – CIA commitments, sub-policies
Як використовувати: ISMS apex doc. The supporting- documents table is the map auditors use to walk your policy tree.
Перегляд
Information Security Policy
Mandatory – ISO/IEC 27001:2022 cl.5.2. The top-level ISMS document: sets direction, approved by top management, communicated to staff and available to interested parties as appropriate.
| Field | Value |
|---|---|
| Document ID | DOC-ISMS-001 |
| Version | N.N |
| Approved by | Top management |
| Effective | YYYY-MM-DD |
| Next review | YYYY-MM-DD |
1. Purpose
Establish management's commitment to protecting the confidentiality, integrity, and availability (CIA) of information.
2. Scope
All information assets within the ISMS scope (DOC-ISMS-000): information in any form, systems, people, processes, facilities.
3. Policy statements
3.1 Core commitments
- Information is protected against unauthorized access (C), unauthorized modification (I), and loss of availability (A).
- Security risk is assessed and treated per the risk methodology (DOC-ISMS-010).
- Security objectives are set, measured, and reviewed (cl.6.2).
- All legal, regulatory, and contractual requirements are met (register: DOC-ISMS-014).
- All staff receive security awareness training; violations lead to disciplinary action.
- Incidents are reported, managed, and learned from (DOC-ISMS-020).
3.2 Roles
| Role | Accountability |
|---|---|
| Top management | ISMS effectiveness, resources, approval |
| ISMS manager / CISO | day-to-day ISMS operation |
| All staff | comply with policies, report incidents |
4. Supporting documents
Subordinate policies implementing this one:
| Doc ID | Topic |
|---|---|
| POL-AUP-001 | Acceptable use |
| POL-ACC-002 | Access control |
| POL-INC-003 | Incident response |
| POL-BCP-004 | Business continuity |
5. Non-compliance
Consequences of violating this policy.
6. Approval & review
Approved by top management; reviewed annually and after significant change.