ISO 27001 ISMS Policy: Requirements and Template
The ISMS policy is the foundational document of your ISO 27001 information security management system. It sets the tone from the top, communicates management commitment, and establishes the framework for setting information security objectives. Without a credible, well-written ISMS policy, your certification audit will stall before it begins. This article explains what the standard requires, what to include, and how to write a policy that works in practice – not just one that passes an audit.
What Is an ISMS Policy?
An ISMS policy is a high-level document that defines the organisation’s overall intention and direction for information security, as formally expressed by top management. It is not a technical document full of firewall rules or encryption algorithms. Instead, it is a strategic commitment document that tells employees, customers, regulators, and auditors what information security means to your organisation and what principles guide your security decisions.
The ISMS policy is the top-tier document in your information security documentation hierarchy. It sits above supporting policies (access control, incident response, business continuity), standards, procedures, and work instructions. Every other security document in your organisation traces its authority back to the ISMS policy.
ISO 27001 Requirements: Clause 5.2
Clause 5.2 of ISO 27001:2022 specifies exactly what the ISMS policy must contain. Top management must establish, implement, and maintain an information security policy that is appropriate to the purpose of the organisation. The policy must include information security objectives or provide the framework for setting them, and it must include a commitment to satisfy applicable requirements related to information security and to continually improve the ISMS.
The policy must be available as documented information, communicated within the organisation, and available to interested parties, as appropriate. This means it cannot be locked in a drawer or buried on an intranet page nobody visits. It must be actively communicated and accessible.
| Clause Requirement | What This Means in Practice | Common Pitfall |
|---|---|---|
| Appropriate to the purpose of the organisation | The policy must reflect your business size, sector, risk profile, and culture | Copying a generic policy from the internet without customisation |
| Include framework for setting objectives | The policy must explain how security objectives are established, monitored, and reviewed | Stating objectives directly in the policy instead of creating a framework for them |
| Commitment to satisfy applicable requirements | Must reference legal, regulatory, contractual, and voluntary obligations | Forgetting to include sector-specific regulations (e.g. GDPR, PCI DSS) |
| Commitment to continual improvement | Must state that the ISMS is reviewed and improved over time | Writing a static policy that does not mention review cycles |
| Available as documented information | Policy must be formally controlled, approved, versioned, and accessible | No version control, no approval signature, or outdated copies circulating |
| Communicated within the organisation | Employees must know the policy exists and understand their responsibilities | Sending a single email and assuming everyone has read and understood it |
What to Include in Your ISMS Policy
A comprehensive ISMS policy should include the following sections. Each section should be concise but complete – aim for two to three pages, not fifty. The policy should be accessible enough that any employee can understand it.
- Purpose: Why the policy exists and what it aims to achieve.
- Scope: Who and what the policy applies to (reference your ISMS scope document).
- Information security principles: The core principles guiding your approach (confidentiality, integrity, availability, and any others specific to your organisation).
- Commitment statements: Management commitment to compliance, risk management, continual improvement, and resource provision.
- Framework for objectives: How information security objectives are set, monitored, measured, and reviewed.
- Roles and responsibilities: Overview of who is responsible for information security (the detailed RACI can be a separate document).
- Review cycle: When and how the policy is reviewed and updated.
- References: Links to supporting policies and related documents.
ISMS Policy Example
The following is a template structure you can adapt for your organisation. Replace the bracketed text with your organisation’s specific details.
| Section | Example Content |
|---|---|
| Policy title | Information Security Management System Policy |
| Document owner | Chief Information Security Officer (CISO) |
| Scope | This policy applies to all employees, contractors, and third parties operating within the ISMS scope as defined in [Document reference]. |
| Statement | [Organisation name] is committed to protecting the confidentiality, integrity, and availability of all information assets. We will comply with all applicable legal, regulatory, and contractual obligations and continually improve our ISMS. |
| Framework for objectives | Information security objectives shall be established annually by top management, aligned with the strategic direction of the organisation. Objectives shall be measurable, monitored quarterly, and reviewed at management review meetings. |
| Commitment | Top management commits to providing the resources necessary to implement, maintain, and improve the ISMS, to communicating the importance of information security throughout the organisation, and to supporting a culture of security awareness. |
| Review | This policy shall be reviewed at least annually by the Information Security Steering Group. Any changes shall be approved by the CISO and communicated to all relevant parties. |
Policy Approval Process
The ISMS policy must be approved by top management to demonstrate leadership commitment. Approval is typically documented through a signature page or electronic authorisation in your document management system. The policy should be approved by the most senior person in the organisation – the CEO, managing director, or board of directors. This is not a delegation item; Clause 5.1 explicitly requires top management to demonstrate leadership and commitment.
The approval process should also include review by relevant stakeholders: the information security manager, legal counsel, compliance, HR, and IT. Their input ensures the policy is accurate, complete, and aligned with other organisational policies.
Communication and Awareness
Having a policy document is not enough. ISO 27001 requires that the policy be communicated within the organisation. This means employees must be aware of the policy, understand their responsibilities under it, and know where to find it. Best practice is to include the ISMS policy in induction training for new employees, reinforce it through annual security awareness training, and display it on the intranet or company portal.
Communication should also extend to interested parties, as appropriate. Customers may request to see your policy during tenders. Regulators may require evidence of your policy commitments. Suppliers may need to understand your security expectations. Make sure your policy is available to external parties in a suitable format, with confidentiality markings if needed.
| Audience | Communication Method | Frequency |
|---|---|---|
| All employees | Induction training, intranet, annual refresher | Upon hire, then annually |
| Contractors and temps | Induction briefing, signed acknowledgement | Upon engagement |
| Management team | Management review, strategy sessions | Quarterly / annually |
| Customers | Sales documentation, tenders, customer portal | Upon request |
| Suppliers | Supplier onboarding, contracts, security questionnaires | Upon onboarding |
Review Cycle
Your ISMS policy must be reviewed at planned intervals. The standard does not prescribe a specific frequency, but annual review is the industry norm. The review should assess whether the policy remains appropriate to the organisation’s purpose, whether it still reflects the legal and regulatory landscape, and whether the commitments made in the policy are being fulfilled. The management review meeting (Clause 9.3) is the ideal forum for policy review.
Reviews should also be triggered by significant events: a major security incident, a change in business direction, a merger or acquisition, a new regulatory requirement, or a change in the risk appetite of the organisation. Each review should result in either confirmation that the policy is still current or an updated version with documented changes.
Links to Other Policies
The ISMS policy is not a standalone document. It sits at the top of a hierarchy of information security policies and procedures. Supporting policies that typically sit below the ISMS policy include:
- Access Control Policy
- Incident Response Policy
- Business Continuity Policy
- Data Classification and Handling Policy
- Password Policy
- Remote Working and Mobile Device Policy
- Supplier Security Policy
- Acceptable Use Policy
Each supporting policy should reference the ISMS policy as its parent document. The ISMS policy should list the key supporting policies and explain how they relate to the overall management system. This creates a coherent, navigable documentation structure that auditors and employees can follow.
Frequently Asked Questions
Can I use a template from the internet for my ISMS policy?
You can use a template as a starting point, but you must customise it to reflect your organisation’s specific context, objectives, and risk profile. Generic policies are a common finding in ISO 27001 audits. A policy that does not mention your specific industry, regulatory obligations, or business model will be challenged by your certification auditor.
Who should sign the ISMS policy?
The policy must be approved by top management. In most organisations, this means the CEO, managing director, or board of directors. The CISO or information security manager can draft the policy, but the approval must come from the highest level of leadership.
How long should the ISMS policy be?
Two to three pages is sufficient for most organisations. The policy should be concise and readable, not a detailed technical document. If your policy exceeds five pages, you are probably including content that belongs in supporting policies or procedures.
How often should the ISMS policy be reviewed?
At least annually. Additional reviews should be triggered by significant events such as security incidents, regulatory changes, mergers, or changes in business strategy. The management review process is the appropriate mechanism for scheduling and conducting reviews.
Is the ISMS policy the same as an information security policy?
For most organisations, yes. ISO 27001 refers to the information security policy. In practice, this document is called the ISMS policy or the information security policy depending on organisational preference. What matters is that it fulfils the requirements of Clause 5.2 and sits at the top of your security documentation hierarchy.
Does the policy need to include specific security controls?
No. Specific controls belong in the Statement of Applicability (SoA) and supporting policies. The ISMS policy is a strategic commitment document. It says what you will do and why. The SoA and supporting policies say how you will do it. Mixing the two levels creates confusion and makes the policy difficult to maintain.
Write Your ISMS Policy with Bitrixme
Your ISMS policy is the public face of your commitment to information security. It must be right. Our ISO 27001 consultants at Bitrixme have helped dozens of organisations draft, approve, and implement ISMS policies that satisfy auditors and inspire confidence in customers. Contact us or reach out on WhatsApp to get started.