Information Security Policy
ISO 27001 · SOC 2Purpose: Set the direction and commitment for protecting [Company]’s information assets and the systems that hold them.
1. Purpose & scope
This policy establishes how [Company] protects the confidentiality, integrity and availability of information. It applies to all employees, contractors, systems and third parties that access [Company] information.
2. Roles & responsibilities
Management approves this policy and provides resources. A designated security owner maintains it. Every user is responsible for following it and reporting incidents.
3. Risk management
[Company] identifies, assesses and treats information-security risks on a defined schedule and after significant change, with risks recorded in a risk register.
4. Controls
[Company] implements access control, secure configuration, logging and monitoring, vulnerability management, encryption of sensitive data, and backup, proportionate to risk.
5. Compliance & review
Non-compliance may result in disciplinary action. This policy is reviewed at least annually and after major changes, and approved by management.
A starter to adapt — not a substitute for legal review. Review with a qualified advisor before adopting.
Get the full editable pack
The starters above are the outline. Share your work email for CyberSigma’s full documentation toolkits — complete, editable policies, procedures, registers and evidence templates for ISO 27001, SOC 2 and DPDP — plus a free gap review.
Need requirements instead of policies? Try the requirements checklist or the Compliance Assistant.
