ISMS Policy
ISMS Policy
The ISMS Policy and Information Security Policy are generally considered the same, acting as the top-level document under ISO 27001 that outlines management’s commitment to security. While editions up to 2005 of the standard separated them, revisions since 2013 combine them into one, with the ISMS Policy often viewed as the governing superset.
The ISO 27001 standard never contained a requirement on the documentation structure, but there were always requirements on what shall be present as documented information. This means organizations are free to structure their ISMS documentation.
The traditional approach is to have 1-2 pages of top-level ISMS Policy and an Information Security Policy that contains controls required by the standard. There may be a strategy document between the two. In this approach, the ISMS Policy includes only the minimum required by the standard: a commitment to continual improvement of the ISMS, a commitment to meet applicable information security requirements, and an approach to setting security objectives. Security requirements may be derived from business strategy, legal and contractual requirements, and current and projected information security risks and threats.
The primary purpose of an ISMS Policy is to wave the flag for employees and other stakeholders (this means communicating the policy should not be limited to employees, but relevant contractors as well). It can be easily made available to interested parties by publishing it on the website. It shall be approved by the top management, which doesn’t necessarily mean the management of the whole organization, but top management of the organization in scope. This ensures that the policy and the objectives set in support of it are aligned with the organization’s strategic direction.
Strategic, long-term security objectives may be included in the ISMS Policy itself, but in most of the cases objectives are more dynamic and should be placed and followed up in a separate document.
For larger organizations an optional strategy document would contain principles and approaches to different aspects and controls of information security.
The principles laid down in the ISMS Policy or strategy document form the basis of enforceable controls to be followed by workforce, as set out in the underlaying Information Security Policy. The key is that this policy is not about principles, but practices – dos and don’ts.
The recent ISO 27001 standard editions allow us to contract all the above into a single document, which is easier to maintain and communicate with personnel doing work under the organization’s control. Nevertheless, this is roughly all the advantages we gain if we do so.
Anyhow top policies are structured, personnel shall be aware of their content, and they must comply with the provisions set out in them. Noncompliance may result in a disciplinary process.
08/06/2026