Information security policy, the document every assessment asks for first
An information security policy is the governing document stating how an organisation protects its information: what it applies to, who is accountable, and the rules staff and suppliers must follow. It is approved at board or executive level, reviewed at a stated interval, and is the first artefact most vendor assessments request. Also called ISP, ISMS policy.
What it should contain
A policy that survives scrutiny states its scope — which entities, systems and people it covers — and names accountability at a level senior enough to enforce it. Beyond that it sets the rules that everything else refers back to: classification and handling of information, access control, acceptable use, cryptography, physical and personnel security, incident reporting, business continuity, and the security expectations placed on suppliers.
Under ISO/IEC 27001 the policy is a required, approved and communicated document with a defined review cycle, and the supplier clauses matter for third-party risk specifically: the 2022 control set expects security requirements to be agreed with suppliers and monitored through the life of the relationship, not stated once at signature.
What to check when a vendor sends you one
Three things, quickly. Is it approved and dated? An unsigned policy with no review date is a template. Does its scope match the service you are buying? Group policies frequently exclude the subsidiary or the platform you are contracting with. Does it match the questionnaire? Where the policy says quarterly access reviews and the questionnaire says annual, one of them is wrong and the discrepancy is worth more than either answer alone.
Cross-checking claims against documents is exactly the kind of work that scales badly by hand and well by machine — it is what ARIA's response validation does against the 157 Universal Controls, which is a more useful reason to collect the policy than filing it as evidence that you asked.
Common questions
What should an information security policy include?
Is an information security policy the same as an ISMS?
How often should it be reviewed?
Related terms and pages
Definitions are the easy part. Evidence is not.
See what your vendors actually expose — scored, monitored and evidenced in one place.