Playbook · Worldwide
Information Security Policy Library
Enterprise buyers and auditors both ask for the same evidence: a documented, approved, and current policy set that matches how you actually operate. This library lists the 18 policies that cover ISO/IEC 27001:2022 Annex A, SOC 2, and common customer security questionnaires, with the contents each policy must include.
Core policy set
- Information Security Policy: scope, objectives, leadership commitment, and accountability model.
- Acceptable Use Policy: permitted use of company systems, data, devices, and generative AI tools.
- Access Control Policy: least privilege, approval, review cadence, and privileged access handling.
- Password and Authentication Policy: credential standards and required multi-factor authentication.
- Data Classification and Handling Policy: labels, permitted storage, sharing, and retention rules.
- Encryption and Key Management Policy: required algorithms, key ownership, and rotation.
- Asset Management Policy: inventory ownership, lifecycle, and secure disposal.
- Endpoint and Mobile Device Policy: enrollment, hardening baseline, and remote wipe.
- Secure Development Policy: code review, secret handling, dependency management, and testing gates.
- Change Management Policy: approval, testing, rollback, and emergency change handling.
- Vulnerability and Patch Management Policy: scan frequency and remediation service levels by severity.
- Logging and Monitoring Policy: sources, retention, alerting, and review responsibilities.
- Incident Response Policy: severity definitions, escalation, regulator notification, and lessons learned.
- Business Continuity and Disaster Recovery Policy: recovery objectives and test frequency.
- Third-Party and Supplier Security Policy: risk tiering, due diligence, and contract requirements.
- Human Resources Security Policy: screening, onboarding, training, and offboarding steps.
- Physical and Environmental Security Policy: facility access and clear desk expectations.
- Privacy and Data Protection Policy: lawful basis, data subject rights, and cross-border transfers.
What every policy must contain
- A version number, effective date, and named approving authority.
- A clear scope statement covering people, systems, and locations.
- Requirements written as testable statements, not aspirations.
- The owner responsible for the policy and the control it governs.
- An exception process with approval authority and expiry date.
- A review date no more than twelve months out.
Keeping the set healthy
- 01Write policies that describe your real operating practice, since auditors test the gap between the two.
- 02Keep standards and procedures separate from policy so technical detail can change without re-approval.
- 03Record acknowledgement from every worker with system access, including contractors.
- 04Review the full set annually and after any major incident, acquisition, or architecture change.
- 05Track every open exception in one register with a named owner and an expiry date.
- 06Map each policy to the framework controls it satisfies so audit evidence requests are quick to answer.
Need a complete, audit-ready policy set?
Dephiant drafts and tailors the full policy library to your operating model, maps it to your target frameworks, and trains your owners to maintain it.