Skip to content

Information Security Policy

What is Information Security Policy?

A formal document that defines an organisation's approach to managing and protecting its information assets. The policy sets the strategic direction for information security and is typically approved by top management.

Information Security

Each of these is named in at least one of the same controls as information security policy. The number is how many controls name both.

What the standards actually require on information security policy

Requirements naming information security policy across 6 standards, quoted from the control text.

Establish information security policy aligned to strategic context, with commitments and continual improvement.

27003-5.2 · Information Security Policy
PCI DSS 4.04 controls

The information security policy is: • Reviewed at least once every 12 months. • Updated as needed to reflect changes to business objectives or risks to the environment

12.1.2 · The information security policy is: • Reviewed at least once every 12 months. • Updated as needed to reflect changes to business objectives or risks to the environment
APRA CPS 2342 controls

The entity must maintain an information security policy framework proportionate to its exposure to vulnerabilities and threats.

CPS234-19 · Information Security Policy Framework
C5 (Germany)1 control

Top management adopts an information security policy and issues it to internal staff, external personnel and cloud customers, setting out why security matters, the security objectives and target level, the core security strategy, and the security organisation.

C5-OIS-02 · Information Security Policy

Institutions shall establish an information security policy approved by the management body, defining the high-level principles and rules to protect the confidentiality, integrity and availability of information.

EBA-GL-3.4.1 · Information security policy

Undertakings establish a written, AMSB-approved information security policy defining principles and rules to protect confidentiality, integrity and availability of information, with roles and responsibilities, communicated to all staff (and relevant service pr...

EIOPA-ICTSG-GL.6 · Information security policy and measures

Questions people ask about information security policy

What is Information Security Policy?
A formal document that defines an organisation's approach to managing and protecting its information assets. The policy sets the strategic direction for information security and is typically approved by top management.
Why is Information Security Policy important for compliance?
Information Security Policy is a key concept in Information Security. Understanding information security policy helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Information Security Policy?
Information Security Policy appears in the requirement text of ISO/IEC 27003:2017, PCI DSS 4.0, APRA CPS 234, C5 (Germany), EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07). Across these standards we have identified 13 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Information Security Policy?
Explore our compliance framework pages to see how information security policy applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Information Security Policy applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.