Skip to content

Information Security Policy

Definition

A high-level governance document that states what the organisation intends to achieve in protecting information, assigns accountability to roles, and sets the scope of the security programme. Approved by senior management or the board. Does not contain technical configuration detail.

Level
High-level governance document
Approved by
Senior management or the board
Content
Intent, accountability, and programme scope
Excludes
Technical configuration detail

Common questions

How does an information security policy differ from a technical standard or procedure in the same organisation?+

The policy states intent and assigns accountability at a level a non-technical board member can approve, while detailed technical standards and step-by-step procedures beneath it translate that intent into specific configuration and operational requirements for practitioners to follow.

Why does board-level approval matter for an information security policy's authority?+

Senior management sign-off signals that security is an organisational priority backed by resources and accountability, which gives the policy the authority to require compliance across departments rather than being treated as an IT-only recommendation.

Related terms

Document Control
The systematic management of all procedural documents in a quality management system, ensuring that the current approved version is in use, all...
Operating Effectiveness
The assessment of whether a control has consistently functioned as designed over the audit period. Requires evidence of actual operation, such as...
Policy Exception
A formal, time-bounded approval to deviate from a policy or standard requirement when the standard control is not achievable. Exceptions must be...
Procedure
A step-by-step operational instruction that tells a specific role how to carry out a task in conformance with the relevant standard. Procedures...
Standard
A document that translates a policy requirement into specific, measurable criteria. For example, a password policy may require strong authentication; the accompanying...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.