Information Security Policy
Definition
A high-level governance document that states what the organisation intends to achieve in protecting information, assigns accountability to roles, and sets the scope of the security programme. Approved by senior management or the board. Does not contain technical configuration detail.
- Level
- High-level governance document
- Approved by
- Senior management or the board
- Content
- Intent, accountability, and programme scope
- Excludes
- Technical configuration detail
Common questions
How does an information security policy differ from a technical standard or procedure in the same organisation?+
The policy states intent and assigns accountability at a level a non-technical board member can approve, while detailed technical standards and step-by-step procedures beneath it translate that intent into specific configuration and operational requirements for practitioners to follow.
Why does board-level approval matter for an information security policy's authority?+
Senior management sign-off signals that security is an organisational priority backed by resources and accountability, which gives the policy the authority to require compliance across departments rather than being treated as an IT-only recommendation.
Related terms
- Document Control
- The systematic management of all procedural documents in a quality management system, ensuring that the current approved version is in use, all...
- Operating Effectiveness
- The assessment of whether a control has consistently functioned as designed over the audit period. Requires evidence of actual operation, such as...
- Policy Exception
- A formal, time-bounded approval to deviate from a policy or standard requirement when the standard control is not achievable. Exceptions must be...
- Procedure
- A step-by-step operational instruction that tells a specific role how to carry out a task in conformance with the relevant standard. Procedures...
- Standard
- A document that translates a policy requirement into specific, measurable criteria. For example, a password policy may require strong authentication; the accompanying...