Information security policy
**Document control**
| Field | Value | |---|---| | Organization | [COMPANY NAME] | | Policy owner | [OWNER NAME / ROLE] | | Approver | [APPROVER NAME / ROLE] | | Version | [VERSION] | | Effective date | [YYYY-MM-DD] | | Next review | [YYYY-MM-DD] |
**Mapped themes:** ISO/IEC 27001:2022 Annex A.5.1; SOC 2 security program governance (educational mapping — not identical requirements).
1. Purpose
This policy sets direction for protecting [COMPANY NAME] information assets and customer data, and for operating an information security program appropriate to our risk and customer commitments.
2. Scope
Applies to all employees, contractors, and systems that create, process, store, or transmit company or customer information, including production cloud environments and corporate identity providers in scope of our security program.
3. Policy statements
- Leadership assigns ownership for information security and reviews the program at planned intervals.
- Risks to information assets are assessed and treated; residual risk is accepted by an authorized role.
- Access to systems and data follows least privilege and need-to-know (see Access control policy).
- Changes to production systems follow approved change management practices.
- Security events are triaged and incidents are managed per the Incident response policy.
- Suppliers with access to company or customer data are assessed proportionate to risk.
- Personnel complete security awareness appropriate to their role.
- This policy and related topic policies are reviewed at least annually and after material changes.
4. Roles
- **Executive sponsor:** [ROLE] — resources and escalation.
- **Policy owner:** [ROLE] — maintenance and exceptions.
- **Control owners:** Named owners for access, change, logging, and vendor processes.
5. Exceptions
Exceptions require documented risk acceptance by [ROLE] with an expiry date and compensating controls.
6. Enforcement
Violations may result in disciplinary action up to termination, consistent with HR policy and applicable law.
7. Related documents
Access control policy; Incident response policy; Change management policy; Vendor risk management policy.
---
**Disclaimer:** Educational template only — not legal advice. Adapt with counsel and your auditor or certification body. ComplianceBase is vendor-neutral and independent.