Back to all 93 controls
    Annex A 5.1
    Organizational

    A.5.1 Policies for information security

    A defined, approved policy set that directs information security.

    What good looks like

    Top-level ISMS policy plus topic-specific policies, approved by management, communicated, and reviewed at planned intervals.

    Evidence an auditor will ask for

    Signed policy documents, approval records, communication evidence, review log.

    Document template for this control

    The Information Security Policy template gives you auditor-ready wording that fulfils Annex A 5.1. Preview the full document before you download the editable version.