What Are ISMS Policies?
ISMS policies are formal documents that define your organization's approach to managing information security. They translate ISO 27001 requirements into actionable rules, responsibilities, and procedures that employees must follow.
Why Policies Matter for ISO 27001
Policies serve three critical purposes:
- Compliance: ISO 27001 explicitly requires several documented policies
- Communication: They tell employees what is expected of them
- Evidence: Auditors need documented policies to verify your ISMS
Mandatory vs. Recommended Policies
Mandatory Policies (Required by ISO 27001)
These policies are explicitly required by the standard:
- Information Security Policy (Clause 5.2) – The overarching policy signed by top management
- Risk Assessment & Treatment Policy (Clause 6.1) – How you identify and handle risks
- Access Control Policy (A.5.15, A.8.2-3) – Who gets access to what
- Document Control Policy (Clause 7.5) – How documents are managed and versioned
Highly Recommended Policies
While not strictly mandatory, auditors expect these:
- Acceptable Use Policy
- Password Policy
- Backup Policy
- Incident Management Policy
- Business Continuity Policy
- Change Management Policy
- Network Security Policy
- Cryptography Policy
- Physical Security Policy
- Supplier Security Policy
- Secure Development Policy
- Data Classification Policy
- Clear Desk & Clear Screen Policy
- BYOD / Mobile Device Policy
- Remote Working Policy
How to Write an Effective ISMS Policy
Structure Template
Every policy should follow this structure:
1. Header
- Policy title
- Version number and date
- Author and approver
- Classification level
- Review date
2. Purpose State why this policy exists in 2-3 sentences.
3. Scope Define who and what the policy applies to.
4. Policy Statements The core rules and requirements. Be specific and actionable:
- ❌ "Users should use strong passwords"
- ✅ "Passwords must be at least 12 characters, containing uppercase, lowercase, numbers, and special characters"
5. Roles & Responsibilities Define who is responsible for what:
- CISO / Information Security Manager
- IT Department
- Department Managers
- All Employees
6. Compliance & Enforcement Describe consequences of non-compliance and how compliance is monitored.
7. Review & Revision How often the policy is reviewed (at least annually) and what triggers a revision.
Writing Tips
- Use clear, simple language – Avoid jargon where possible
- Be specific – Measurable requirements are easier to audit
- Align with risk assessment – Policies should address identified risks
- Keep it practical – Policies nobody can follow are useless
- Version control – Track all changes with dates and approvers
Policy-by-Policy Guide
Information Security Policy
The top-level policy that establishes management's direction for information security. It should:
- State commitment to information security
- Define security objectives
- Reference the ISMS scope
- Assign overall responsibility
- Commit to continual improvement
Access Control Policy
Defines rules for granting, reviewing, and revoking access:
- Need-to-know and least privilege principles
- User registration and de-registration process
- Privileged access management
- Access review frequency (quarterly recommended)
- Multi-factor authentication requirements
Incident Management Policy
Covers how security incidents are handled:
- Incident classification levels
- Reporting procedures and timelines
- Response and escalation procedures
- Evidence preservation requirements
- Post-incident review process
- Notification obligations (regulatory, customer)
Business Continuity Policy
Ensures critical operations continue during disruptions:
- Business impact analysis requirements
- Recovery time and point objectives (RTO/RPO)
- Continuity plan testing frequency
- Crisis communication procedures
Use our RTO/RPO Helper to calculate recovery objectives.
Free Policy Templates
Download our complete set of 40+ policy templates from the Documents Library:
- All templates follow the structure above
- Customizable for your organization
- Available in PDF (free) and editable Word format
- Covers all Annex A control areas
Common Policy Mistakes
- Copy-paste without customizing – Generic policies fail audits
- Too long and complex – Aim for 3-8 pages per policy
- No review schedule – Policies must be reviewed at least annually
- Missing approval signatures – Policies need formal approval
- Not communicated – Staff must be aware of relevant policies
Conclusion
Well-written ISMS policies are the backbone of your ISO 27001 compliance. Start with the mandatory policies, then expand based on your risk assessment findings. Use our free templates as a starting point and customize them for your organization.
Found this article helpful?
Share it with your colleagues.
