P-20 Information Security Policy
File Reference : P-20 Information Security Policy
Date File Updated 28-09-2023
File Format MS Word
No. of files 1
Category Policies
Tags: ISO 27001, 5.2, IMS1 2.1, IMS1 8.5
  • £10.00

  or  

Login to Download


This policy outlines the company’s commitment to maintain an information security management system that meets the requirements of the ISO 27001:2013 standard.

It includes commitments to protecting the confidentiality, integrity and availability of information assets from all threats whether internal, external, deliberate or accidental.

It details the controls in place to ensure information security, compliance with applicable requirements of the ISO 27001 standard, mechanisms in place for continuous improvement of information security…etc.

This policy is a requirement for ISO 27001:2013 compliance and can be edited to suit. However, care must be taken when amending this document if the intent is for it to be used to satisfy the requirements of ISO 27001 compliance as there are some elements that the standard requires the policy to cover: -

  • A framework for setting information security objectives
  • A commitment to satisfy applicable requirements
  • A commitment to continual improvements of the integrated management systems.

Like all other policies this should be retained as documented information, filed correctly and made available to all interested parties.

The information classification label on this policy is [Public].


There are currently no comments for this document.

Add a Comment

Please Login or Subscribe to add Comments.