Step 5 · Plan and implementation
Information security policy and topic-specific policies Management’s direction, in writing.
The information security policy sets management’s direction, and topic-specific policies cover the details. Both must be approved, communicated and reviewed regularly.
What it is about
ISO/IEC 27001 clause 5.2 requires an information security policy from top management, with objectives and a commitment to meet requirements and to improve continually. Annex A 5.1 adds topic-specific policies that are approved by management, published, communicated to staff and reviewed at planned intervals.
- MFA for all admin accountsITdone
- Update the emergency manualCISOin progress
- Review cloud supplierPurchasingoverdue
23 of 46 measures implemented
Sample values
How to go about it
- 01
Write a policy with objectives and management’s accountability.
- 02
Add topic-specific policies, for example on access, cryptography, backup and mobile devices.
- 03
Approve, communicate and record acknowledgement.
- 04
Review at planned intervals and when things change.
Common mistakes
- Policies from templates that nobody follows.
- No approval by management.
- Staff do not know the rules.
What an auditor wants to see
- Approved policy with date and version
- Register of policies
- Evidence of communication and acknowledgement
How UniqSuite helps
In UniqSuite you start from a template that shows which requirements it covers, and adapt it. Approval authority, version, effective date and next review date are recorded with it.
References
- ISO/IEC 27001, clause 5.2
- ISO/IEC 27001, Annex A 5.1
- Section 30(2) No. 1 BSIG: policies on risk analysis and information system security
Frequently asked questions
How many policies do we need?
As many as your risks and measures call for. A few that people follow beat a folder nobody reads.
Who approves the policy?
Top management. Under NIS2 this fits its duty to implement and oversee the measures.
How often are the policies reviewed?
ISO 27001 requires planned intervals and a review when significant changes occur. For the digital services covered by Implementing Regulation (EU) 2024/2690, the management bodies review the security policy at least annually and after significant incidents.
Must customers or authorities be able to see the policy?
ISO 27001 clause 5.2 requires it to be available to interested parties, as appropriate. You decide who receives it and in what form.
Must all staff know every policy?
The information security policy, yes: under clause 7.3 everyone doing work under your control must be aware of it. Topic-specific policies must be known by the people they apply to.
See what this looks like in UniqSuite.
In half an hour we walk you through it with your own questions.
