Step 5 · Plan and implementation

Information security policy and topic-specific policies Management’s direction, in writing.

The information security policy sets management’s direction, and topic-specific policies cover the details. Both must be approved, communicated and reviewed regularly.

What it is about

ISO/IEC 27001 clause 5.2 requires an information security policy from top management, with objectives and a commitment to meet requirements and to improve continually. Annex A 5.1 adds topic-specific policies that are approved by management, published, communicated to staff and reviewed at planned intervals.

Step 5Plan and implementation
Open14
In progress9
Done23
  • MFA for all admin accountsITdone
  • Update the emergency manualCISOin progress
  • Review cloud supplierPurchasingoverdue

23 of 46 measures implemented

Sample values

How to go about it

  1. 01

    Write a policy with objectives and management’s accountability.

  2. 02

    Add topic-specific policies, for example on access, cryptography, backup and mobile devices.

  3. 03

    Approve, communicate and record acknowledgement.

  4. 04

    Review at planned intervals and when things change.

Common mistakes

  • Policies from templates that nobody follows.
  • No approval by management.
  • Staff do not know the rules.

What an auditor wants to see

  • Approved policy with date and version
  • Register of policies
  • Evidence of communication and acknowledgement

How UniqSuite helps

In UniqSuite you start from a template that shows which requirements it covers, and adapt it. Approval authority, version, effective date and next review date are recorded with it.

References

  • ISO/IEC 27001, clause 5.2
  • ISO/IEC 27001, Annex A 5.1
  • Section 30(2) No. 1 BSIG: policies on risk analysis and information system security

Frequently asked questions

How many policies do we need?

As many as your risks and measures call for. A few that people follow beat a folder nobody reads.

Who approves the policy?

Top management. Under NIS2 this fits its duty to implement and oversee the measures.

How often are the policies reviewed?

ISO 27001 requires planned intervals and a review when significant changes occur. For the digital services covered by Implementing Regulation (EU) 2024/2690, the management bodies review the security policy at least annually and after significant incidents.

Must customers or authorities be able to see the policy?

ISO 27001 clause 5.2 requires it to be available to interested parties, as appropriate. You decide who receives it and in what form.

Must all staff know every policy?

The information security policy, yes: under clause 7.3 everyone doing work under your control must be aware of it. Topic-specific policies must be known by the people they apply to.

See what this looks like in UniqSuite.

In half an hour we walk you through it with your own questions.

→Demo request

Show us your questions.

We will get back to you within two working days and arrange a demo of about 30 minutes – built around your own requirements.

Please fill in.

Please fill in.

Please fill in.

Please enter a valid email address.

Please use digits, spaces and + ( ) / - only.

We use your details solely to answer your request. Details in our privacy policy.