Information Security Policy
What is Information Security Policy?
A formal document that defines an organisation's approach to managing and protecting its information assets. The policy sets the strategic direction for information security and is typically approved by top management.
Terms that appear alongside information security policy
Each of these is named in at least one of the same controls as information security policy. The number is how many controls name both.
- policy 34 shared controls
- policy framework 10 shared controls
- security policy framework 10 shared controls
- roles and responsibilities 4 shared controls
- ciso 4 shared controls
- governance 4 shared controls
- compliance 4 shared controls
- encryption 3 shared controls
Frameworks that govern information security policy
What the standards actually require on information security policy
Requirements naming information security policy across 6 standards, quoted from the control text.
Establish information security policy aligned to strategic context, with commitments and continual improvement.
27003-5.2 · Information Security Policy →The information security policy is: • Reviewed at least once every 12 months. • Updated as needed to reflect changes to business objectives or risks to the environment
12.1.2 · The information security policy is: • Reviewed at least once every 12 months. • Updated as needed to reflect changes to business objectives or risks to the environment →The entity must maintain an information security policy framework proportionate to its exposure to vulnerabilities and threats.
CPS234-19 · Information Security Policy Framework →Top management adopts an information security policy and issues it to internal staff, external personnel and cloud customers, setting out why security matters, the security objectives and target level, the core security strategy, and the security organisation.
C5-OIS-02 · Information Security Policy →Institutions shall establish an information security policy approved by the management body, defining the high-level principles and rules to protect the confidentiality, integrity and availability of information.
EBA-GL-3.4.1 · Information security policy →Undertakings establish a written, AMSB-approved information security policy defining principles and rules to protect confidentiality, integrity and availability of information, with roles and responsibilities, communicated to all staff (and relevant service pr...
EIOPA-ICTSG-GL.6 · Information security policy and measures →Questions people ask about information security policy
What is Information Security Policy?
Why is Information Security Policy important for compliance?
Which compliance frameworks address Information Security Policy?
Where can I learn more about Information Security Policy?
See how Information Security Policy applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.