Information Security Policy template
The core structure of the organisation's high level security policy.
Security policy is a high-level document approved by management. Main elements: 1) Objective and scope; 2) Management obligations and responsibilities; 3) Security principles (confidentiality, integrity, accessibility); 4) Compliance requirements (ISO, GDPR, NIS2, binding national and international laws and regulations); 5) Security roles and responsibilities (CISO, ISMS coordinator, data controller); 6) Relationship to other policies (parles, incidents, remote work); 7) Consequences of infringements; 8) Review cycle (annually or following significant changes). The policy must be approved by the management and communicated to all staff.