Playbook · Worldwide

Information Security Policy Library

Enterprise buyers and auditors both ask for the same evidence: a documented, approved, and current policy set that matches how you actually operate. This library lists the 18 policies that cover ISO/IEC 27001:2022 Annex A, SOC 2, and common customer security questionnaires, with the contents each policy must include.

Core policy set

  • Information Security Policy: scope, objectives, leadership commitment, and accountability model.
  • Acceptable Use Policy: permitted use of company systems, data, devices, and generative AI tools.
  • Access Control Policy: least privilege, approval, review cadence, and privileged access handling.
  • Password and Authentication Policy: credential standards and required multi-factor authentication.
  • Data Classification and Handling Policy: labels, permitted storage, sharing, and retention rules.
  • Encryption and Key Management Policy: required algorithms, key ownership, and rotation.
  • Asset Management Policy: inventory ownership, lifecycle, and secure disposal.
  • Endpoint and Mobile Device Policy: enrollment, hardening baseline, and remote wipe.
  • Secure Development Policy: code review, secret handling, dependency management, and testing gates.
  • Change Management Policy: approval, testing, rollback, and emergency change handling.
  • Vulnerability and Patch Management Policy: scan frequency and remediation service levels by severity.
  • Logging and Monitoring Policy: sources, retention, alerting, and review responsibilities.
  • Incident Response Policy: severity definitions, escalation, regulator notification, and lessons learned.
  • Business Continuity and Disaster Recovery Policy: recovery objectives and test frequency.
  • Third-Party and Supplier Security Policy: risk tiering, due diligence, and contract requirements.
  • Human Resources Security Policy: screening, onboarding, training, and offboarding steps.
  • Physical and Environmental Security Policy: facility access and clear desk expectations.
  • Privacy and Data Protection Policy: lawful basis, data subject rights, and cross-border transfers.

What every policy must contain

  • A version number, effective date, and named approving authority.
  • A clear scope statement covering people, systems, and locations.
  • Requirements written as testable statements, not aspirations.
  • The owner responsible for the policy and the control it governs.
  • An exception process with approval authority and expiry date.
  • A review date no more than twelve months out.

Keeping the set healthy

  1. 01Write policies that describe your real operating practice, since auditors test the gap between the two.
  2. 02Keep standards and procedures separate from policy so technical detail can change without re-approval.
  3. 03Record acknowledgement from every worker with system access, including contractors.
  4. 04Review the full set annually and after any major incident, acquisition, or architecture change.
  5. 05Track every open exception in one register with a named owner and an expiry date.
  6. 06Map each policy to the framework controls it satisfies so audit evidence requests are quick to answer.

Need a complete, audit-ready policy set?

Dephiant drafts and tailors the full policy library to your operating model, maps it to your target frameworks, and trains your owners to maintain it.