A.5.1
Policies for information security
ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026
Objective
Define, approve, publish, and maintain information security policies that set direction for the ISMS and are appropriate to the organization's purpose and context.
Points of focus
- Policy topics cover ISMS scope needs
- Leadership approval and version control
- Communication and acknowledgement where required
- Periodic review triggered by major change
Implementation notes
Keep a short, approved information security policy plus topic policies (access, acceptable use, incident, vendor) that match how the SaaS actually runs. Store versions in a controlled repo or GRC tool with owners and review dates. When you change IdP, cloud estate, or product scope, trigger a policy delta review. Align wording with SOC 2 system description claims so dual-track evidence stays coherent. Prefer linking engineers to operating runbooks rather than duplicating tool-specific steps inside legalistic policy text.
Audit tip: Bring the current policy PDF plus approval record and the last review decision — not a draft folder.
Evidence auditors typically request:
- Board or leadership-approved information security policy
- Policy index with owners and next-review dates
- Distribution / acknowledgement records for workforce
- Change history after significant risk or org changes
Common gaps
- Policies never reviewed after initial certification rush
- Engineering practices contradict written policy
- No evidence of communication beyond posting on a wiki
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.5.1 | This control |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.5.1)