TPRM glossary

Information security policy, the document every assessment asks for first

An information security policy is the governing document stating how an organisation protects its information: what it applies to, who is accountable, and the rules staff and suppliers must follow. It is approved at board or executive level, reviewed at a stated interval, and is the first artefact most vendor assessments request. Also called ISP, ISMS policy.

What it should contain

A policy that survives scrutiny states its scope — which entities, systems and people it covers — and names accountability at a level senior enough to enforce it. Beyond that it sets the rules that everything else refers back to: classification and handling of information, access control, acceptable use, cryptography, physical and personnel security, incident reporting, business continuity, and the security expectations placed on suppliers.

Under ISO/IEC 27001 the policy is a required, approved and communicated document with a defined review cycle, and the supplier clauses matter for third-party risk specifically: the 2022 control set expects security requirements to be agreed with suppliers and monitored through the life of the relationship, not stated once at signature.

What to check when a vendor sends you one

Three things, quickly. Is it approved and dated? An unsigned policy with no review date is a template. Does its scope match the service you are buying? Group policies frequently exclude the subsidiary or the platform you are contracting with. Does it match the questionnaire? Where the policy says quarterly access reviews and the questionnaire says annual, one of them is wrong and the discrepancy is worth more than either answer alone.

Cross-checking claims against documents is exactly the kind of work that scales badly by hand and well by machine — it is what ARIA's response validation does against the 157 Universal Controls, which is a more useful reason to collect the policy than filing it as evidence that you asked.

Common questions

What should an information security policy include?
Scope, named accountability, and the rules that everything else derives from: information classification and handling, access control, acceptable use, cryptography, physical and personnel security, incident reporting, continuity, and supplier security requirements. It should also state its approval date and review cycle.
Is an information security policy the same as an ISMS?
No. The policy is one document; an information security management system is the whole framework of policies, processes, roles, risk assessments and reviews that ISO 27001 certifies. The policy sits at the top of an ISMS and is required by it, but on its own it certifies nothing.
How often should it be reviewed?
At planned intervals — annually is the common commitment — and additionally whenever something significant changes: a major incident, a new regulatory obligation, a merger, or a substantial change in systems. What matters to an assessor is that the stated interval exists and has actually been met.

Definitions are the easy part. Evidence is not.

See what your vendors actually expose — scored, monitored and evidenced in one place.