Home | News | What policies are required for ISO27001 and what should be in them?

News

What policies are required for ISO27001 and what should be in them?

What policies Are Required For Iso27001 And What Should Be In Them?

What policies are required for ISO27001 and what should be in them?

ISO 27001 certification involves policies, but one of the biggest mistakes businesses make is assuming they need dozens of separate policy documents simply because somebody has handed them a template pack.

ISO/IEC 27001:2022 takes a more practical approach.

The standard requires an organisation to establish, operate, maintain and continually improve an Information Security Management System, commonly known as an ISMS. Policies form an important part of that system because they explain the organisation’s direction, rules and expectations for protecting information.

However, ISO 27001 does not say that every Annex A control needs its own individual policy.

The Information Security Policy has a clear requirement within clause 5.2. Annex A control 5.1 also addresses information security policies and topic-specific policies. Additional policies should then reflect the organisation’s risks, business needs, legal obligations, contractual commitments and selected controls.

This distinction matters because a small professional services business should not blindly adopt the same policy structure as a multinational technology company.

Your policies should describe how your organisation actually manages information security.

UK Cyber Compliance helps organisations manage ISO 27001 through an automated and AI-driven compliance platform, bringing together policies, risk assessments, controls, the Statement of Applicability, evidence and audit preparation within a structured system.

UK Cyber Compliance (a part of UK Cyber Security Group) provides these services and has a platform to make certification much easier and cheaper.

Start with the policy ISO 27001 clearly requires

The most important policy is the Information Security Policy.

Clause 5.2 of ISO/IEC 27001 requires top management to establish an information security policy.

This is not simply an IT department document.

It should represent the organisation’s overall commitment to information security and provide direction for the ISMS.

ISO identifies ISO/IEC 27001:2022 as the current international standard for information security management systems and states that it helps organisations establish, implement, maintain and continually improve their ISMS.

What should the Information Security Policy contain?

A strong Information Security Policy should address:

  • The purpose of information security within the organisation
  • Commitment from senior management
  • The organisation’s information security objectives or framework for setting them
  • Commitment to satisfy applicable information security requirements
  • Commitment to continual improvement of the ISMS
  • Overall responsibilities
  • Expectations for employees and relevant external parties
  • How the organisation protects confidentiality, integrity and availability
  • Policy ownership
  • Approval
  • Review arrangements
  • How significant changes trigger another review

Keep the document proportionate.

A concise Information Security Policy that senior management understands and employees can follow provides more value than a lengthy document filled with generic statements.

Annex A also expects policy governance

Annex A control 5.1 focuses specifically on policies for information security.

The control expects the organisation to define an information security policy and appropriate topic-specific policies, gain management approval, communicate them to relevant people and review them at planned intervals or following significant change.

That does not mean you automatically need a separate policy for every security subject.

You can combine related areas where that approach makes sense.

For example, one IT Security Policy could potentially cover acceptable use, endpoint security, removable media and software management if the document remains clear.

The important question is whether your policies properly support the controls that your organisation has determined are necessary.

what is iso 27001

ISO 27001 is the international requirements standard for information security management systems.

It gives organisations a structured way to manage information security risk through people, processes and technology.

The standard focuses heavily on confidentiality, integrity and availability.

Confidentiality means information reaches only authorised people.

Integrity means information remains accurate and protected from unauthorised alteration.

Availability means information and systems remain accessible when authorised users need them.

ISO states that the standard applies to organisations across sectors and allows an organisation to adapt its risk management approach to its circumstances.

Policies support this process by translating management decisions and security expectations into understandable rules.

Do not confuse mandatory documentation with mandatory policies

This distinction prevents a lot of unnecessary work.

ISO 27001 requires several pieces of documented information, but not all of them are policies.

For example, an organisation normally needs documented information covering:

  • ISMS scope
  • Information Security Policy
  • Risk assessment process
  • Risk treatment process
  • Statement of Applicability
  • Risk Treatment Plan
  • Information security objectives
  • Risk assessment results
  • Risk treatment results
  • Internal audit records
  • Management review results
  • Corrective action records

A Statement of Applicability is important, but it is not a policy.

A risk register is important, but it is not a policy.

An internal audit report is evidence, not a policy.

Keeping these distinctions clear creates a cleaner ISMS.

Let the risk assessment drive your supporting policies

The organisation’s risk assessment should strongly influence which additional policies it needs.

Imagine a business that relies heavily on Microsoft 365, laptops, remote employees and several cloud suppliers.

Its risks could make policies covering access control, remote working, cloud security, acceptable use, supplier security, backup and incident management important.

A manufacturing organisation may require additional rules around operational systems, physical access and specialist equipment.

A software company may place greater emphasis on secure development, source code protection and change control.

Build policies around actual risk.

Do not create documents simply because another company has them.

Access Control Policy

Access control is one of the most important areas for many ISO 27001 environments.

Annex A contains controls covering access control, identity management, authentication information and access rights.

A dedicated Access Control Policy often makes sense where these controls apply.

What should an Access Control Policy contain?

It can cover:

  • Principle of least privilege
  • User account approval
  • Unique user identities
  • Privileged access
  • Administrator accounts
  • Authentication requirements
  • Multi-factor authentication
  • Password management
  • Joiner processes
  • Employee role changes
  • Leaver processes
  • Periodic access reviews
  • Supplier access
  • Temporary accounts
  • Remote access
  • Shared account restrictions
  • Emergency access
  • Removal of unnecessary access

The policy should match actual technical arrangements.

If it says privileged access receives review every quarter, your organisation should perform and record those reviews.

An auditor can ask for the evidence.

Acceptable Use Policy

An Acceptable Use Policy tells employees and relevant contractors how the organisation expects them to use information and technology.

Annex A control 5.10 addresses acceptable use of information and associated assets.

Where this control applies, documented rules can provide a practical way to implement it.

What should an Acceptable Use Policy contain?

Consider areas such as:

  • Business use of company equipment
  • Personal use
  • Email
  • Internet access
  • Cloud services
  • Approved applications
  • Unauthorised software
  • Data handling
  • Removable media
  • Company devices
  • Personal devices where relevant
  • Password and authentication responsibilities
  • Physical protection of equipment
  • Reporting lost equipment
  • Reporting suspicious activity
  • Leaving devices unattended
  • Returning company assets

Write rules employees can understand.

Highly technical wording often reduces the policy’s effectiveness.

Information Classification Policy

Information does not require the same level of protection in every situation.

A public marketing document does not normally require the same controls as confidential employee records or sensitive customer information.

An Information Classification Policy can explain how employees identify and handle information according to its sensitivity.

What should an Information Classification Policy contain?

It can define:

  • Classification categories
  • Criteria for each category
  • Who assigns classifications
  • Labelling requirements
  • Storage rules
  • Access expectations
  • Transfer requirements
  • Printing rules
  • Sharing restrictions
  • Retention considerations
  • Secure disposal
  • Reclassification
  • Responsibilities

Keep the classification system simple enough for employees to use consistently.

If staff cannot decide which category applies, the policy becomes difficult to operate.

Asset Management Policy

Information security starts with knowing what needs protection.

An Asset Management Policy can support controls around the inventory and acceptable use of information and associated assets.

What should an Asset Management Policy contain?

Consider:

  • What the organisation regards as an asset
  • Asset ownership
  • Inventory responsibilities
  • Asset registration
  • Asset review
  • Company equipment
  • Software
  • Cloud services
  • Information assets
  • Return of assets
  • Disposal
  • Loss or theft
  • Asset lifecycle responsibilities

The organisation should also maintain suitable records.

A policy saying that assets receive inventory control provides little assurance when nobody can produce an accurate inventory.

Supplier Security Policy

Third-party suppliers can create significant information security risk.

Cloud providers, managed IT companies, software vendors, professional advisers and other external organisations may all process information or access systems.

A Supplier Security Policy can establish how the organisation evaluates and manages those relationships.

What should a Supplier Security Policy contain?

Useful areas include:

  • Security due diligence
  • Risk assessment
  • Approval responsibilities
  • Information access
  • Contractual security requirements
  • Confidentiality
  • Data protection
  • Incident notification
  • Subcontracting
  • Service monitoring
  • Periodic reviews
  • Changes to supplier services
  • Termination
  • Return or deletion of information

Apply stronger controls to higher-risk suppliers.

You do not need the same level of assessment for every external organisation.

Cloud Security Policy

Many organisations now depend on cloud services for email, collaboration, file storage, finance, customer management and many other functions.

ISO/IEC 27001:2022 added a specific Annex A control addressing information security for the use of cloud services.

A Cloud Security Policy can establish how the organisation selects, approves, configures, uses and exits cloud services.

What should a Cloud Security Policy contain?

It could address:

  • Approval before adopting a cloud service
  • Security assessment
  • Identity management
  • Authentication
  • Administrator access
  • Data location considerations
  • Data protection
  • Supplier responsibilities
  • Customer responsibilities
  • Backup
  • Logging
  • Monitoring
  • Contract requirements
  • Incident reporting
  • Service changes
  • Exit arrangements
  • Information retrieval
  • Secure deletion

Cloud responsibility should remain clear.

Using Microsoft 365 or another established platform does not transfer every information security responsibility to the supplier.

Remote Working Policy

Hybrid and remote working can expose information outside the traditional office.

Annex A includes a remote working control, so organisations where employees work remotely may need clear rules.

What should a Remote Working Policy contain?

Consider:

  • Approved equipment
  • Secure internet access
  • Device protection
  • Physical security
  • Confidential conversations
  • Screen privacy
  • Information storage
  • Printing
  • Company information at home
  • Public locations
  • Travel
  • Lost or stolen equipment
  • Remote access
  • Security incident reporting
  • Family or third-party access to work devices

The policy should reflect how employees really work rather than assuming everyone sits permanently inside a controlled office.

Mobile Device and personal device rules

Phones and tablets often access business email, cloud applications and company information.

Your organisation should decide whether it allows personal equipment to access company resources.

Where relevant, policy content can cover:

  • Approved devices
  • Supported operating systems
  • Security updates
  • Authentication
  • Screen locks
  • Encryption
  • Company information
  • Lost devices
  • Remote removal of company information
  • Personal device responsibilities
  • Separation of business and personal information
  • Access withdrawal

You can include these rules inside a broader acceptable use or endpoint policy instead of creating another standalone document.

Backup Policy

Backup requirements should reflect business and information security needs.

Annex A control 8.13 addresses information backup.

A Backup Policy can establish expectations while operational records prove that the organisation follows them.

What should a Backup Policy contain?

Useful areas include:

  • Information and systems requiring backup
  • Backup frequency
  • Retention
  • Backup protection
  • Access
  • Encryption where appropriate
  • Storage
  • Recovery responsibilities
  • Monitoring
  • Failed backup handling
  • Restore testing
  • Review

Do not stop at successful backup reports.

Test whether you can restore important information.

A successful recovery test provides much stronger assurance that the process works.

Incident Management Policy

Cyber incidents can happen even when an organisation has strong preventive controls.

A clear incident management policy helps employees and managers respond quickly.

What should an Incident Management Policy contain?

Include:

  • Definition of a security event
  • Definition of a security incident
  • Reporting channels
  • Responsibilities
  • Initial assessment
  • Severity
  • Escalation
  • Containment
  • Investigation
  • Evidence handling
  • Recovery
  • Communications
  • Customer notification
  • Regulatory notification where applicable
  • Lessons learned
  • Follow-up actions

Employees should know how to report something suspicious.

A complicated process can discourage reporting.

Vulnerability and security update policy

Organisations need a consistent approach to technical vulnerabilities.

A policy or procedure can define how the business discovers, assesses and addresses weaknesses.

What should it contain?

Consider:

  • Vulnerability information sources
  • Scanning
  • Risk assessment
  • Security updates
  • Responsibilities
  • Prioritisation
  • Emergency action
  • Unsupported software
  • Exceptions
  • Remediation tracking
  • Verification
  • Reporting

The process should connect with risk management.

A serious vulnerability that cannot receive immediate remediation may need a documented risk decision and compensating controls.

Logging and Monitoring Policy

Logs can help identify suspicious activity, investigate incidents and provide accountability.

Where logging and monitoring controls apply, a policy can establish what the organisation expects.

What should a Logging and Monitoring Policy contain?

It may cover:

  • Systems requiring logging
  • Security events
  • Administrator activity
  • Access events
  • Log protection
  • Access to logs
  • Retention
  • Time synchronisation
  • Monitoring responsibilities
  • Alerts
  • Escalation
  • Review frequency
  • Investigation

Do not collect logs with no purpose.

Someone needs to know when to review them and what action to take.

Cryptography Policy

Some organisations benefit from a dedicated policy covering encryption and cryptographic controls.

Others can include these requirements within broader security documents.

What should a Cryptography Policy contain?

Consider:

  • When encryption is required
  • Approved encryption arrangements
  • Information at rest
  • Information in transit
  • Key management
  • Responsibilities
  • Mobile devices
  • Removable media
  • Backups
  • Cloud services
  • Certificate management
  • Key loss
  • Key revocation

The requirements should reflect actual risk and applicable obligations.

Information Transfer Policy

Businesses regularly send information by email, cloud platforms, file-sharing services and other channels.

A policy can help define which methods employees may use.

What should an Information Transfer Policy contain?

Useful content includes:

  • Approved transfer methods
  • Classification considerations
  • Recipient checking
  • Encryption
  • External sharing
  • Email
  • File-sharing platforms
  • Physical transfer
  • Confidential information
  • Customer requirements
  • Accidental disclosure
  • Reporting errors

Simple rules can prevent common mistakes such as emailing confidential information to the wrong recipient.

Data Retention and Secure Disposal Policy

Organisations should not retain information indefinitely simply because storage remains available.

Retention needs can arise from legislation, contracts, operational needs and information security risk.

What should the policy contain?

It can cover:

  • Retention responsibilities
  • Retention periods
  • Legal considerations
  • Contractual requirements
  • Employee records
  • Customer information
  • Security records
  • Backup retention
  • Disposal approval
  • Electronic deletion
  • Physical destruction
  • Supplier responsibilities
  • Evidence of disposal

Retention schedules often provide supporting detail.

Physical Security Policy

Information security includes physical protection.

Depending on the organisation, relevant policies can cover offices, secure areas, equipment and visitors.

What should a Physical Security Policy contain?

Consider:

  • Building access
  • Visitors
  • Access cards
  • Keys
  • Restricted areas
  • Server or communications rooms
  • Equipment security
  • Clear desks
  • Clear screens
  • Paper information
  • Working outside offices
  • Environmental threats
  • Asset removal
  • Secure disposal

A fully remote organisation may need a different approach from a business operating several physical sites.

Clear Desk and Clear Screen Policy

Some organisations make this a separate policy.

Others include it within physical security or acceptable use rules.

It can address:

  • Locking screens
  • Protecting papers
  • Storing confidential information
  • Whiteboards
  • Printers
  • Meeting rooms
  • Disposal
  • Visitor visibility

Again, create a separate document only when it improves clarity.

Human Resources Security Policy

People security begins before someone joins and continues when they leave.

Policies or procedures may cover:

  • Pre-employment checks where appropriate
  • Contracts
  • Confidentiality
  • Security responsibilities
  • Induction
  • Awareness
  • Disciplinary processes
  • Changes in employment
  • Termination
  • Return of equipment
  • Access removal
  • Continuing confidentiality obligations

HR and IT processes should work together.

A leaver process that removes building access but forgets cloud accounts leaves a security gap.

Secure Development Policy

Organisations that develop software or systems may need documented secure development requirements.

If the organisation does not develop software, some related controls may not apply.

What should a Secure Development Policy contain?

Where relevant, it can address:

  • Secure development principles
  • Security requirements
  • Development environments
  • Testing
  • Code review
  • Source code access
  • Change control
  • Vulnerability management
  • Third-party components
  • Secrets and credentials
  • Security testing
  • Release approval
  • Separation of environments

The content should reflect the organisation’s actual development process.

Change Management Policy

Uncontrolled changes can introduce vulnerabilities or disrupt important systems.

A Change Management Policy can establish a structured process.

What should it contain?

Consider:

  • Change requests
  • Business justification
  • Risk assessment
  • Security considerations
  • Approval
  • Testing
  • Rollback
  • Emergency changes
  • Responsibilities
  • Implementation records
  • Post-change review

Smaller organisations can keep the process simple while still maintaining control.

Business Continuity and ICT Readiness Policy

ISO 27001 expects organisations to consider information security during disruption and ICT readiness for business continuity where those controls apply.

A continuity policy can connect information security with wider business resilience.

What should it contain?

Useful areas include:

  • Critical business processes
  • Critical systems
  • Dependencies
  • Recovery priorities
  • Responsibilities
  • Communications
  • Alternative working arrangements
  • Suppliers
  • Backup and recovery
  • Testing
  • Review
  • Lessons from exercises or incidents

Policies should connect with actual continuity and recovery plans.

Privacy and Data Protection Policy

ISO 27001 does not replace UK data protection law.

However, privacy and protection of personal information may form an important part of the organisation’s legal and regulatory requirements.

A UK organisation may therefore maintain a Data Protection Policy that addresses:

  • Data protection principles
  • Lawful processing
  • Individual rights
  • Responsibilities
  • Personal information handling
  • Security
  • Retention
  • Data breaches
  • Supplier processing
  • International transfers where applicable
  • Data Protection Impact Assessments where needed
  • Training

The policy should connect with the organisation’s legal and regulatory register.

Who needs iso 27001 certification

Any organisation can use ISO 27001, regardless of sector.

ISO states that the standard can support organisations across economic sectors and allows businesses to adapt information security risk management to their circumstances.

Certification can become particularly valuable for organisations that:

  • Handle sensitive information
  • Process customer data
  • Provide technology services
  • Supply larger organisations
  • Participate in tenders
  • Work with public-sector customers
  • Depend heavily on digital services
  • Need independent information security assurance
  • Face contractual security requirements

Some organisations implement ISO 27001 without pursuing certification.

Others seek independent certification because customers, procurement requirements or business objectives make external assurance important.

What is ISO 27001 Certification?

ISO 27001 certification is independent confirmation that an organisation’s ISMS conforms to ISO/IEC 27001 within its stated certification scope.

ISO itself does not certify individual companies.

Certification bodies perform the assessment.

In the UK, UKAS accredits certification bodies and states that accreditation gives the market confidence in their competence and the reliability of their certification activity. UKAS identifies ISO/IEC 27006-1:2024 as the current specialist standard for bodies auditing and certifying information security management systems.

Accredited certification therefore adds independent assurance to the organisation’s own claims about information security management.

ISO 27001 Certification Levels

ISO 27001 does not use official bronze, silver, gold or similar certification levels.

An organisation defines its ISMS scope and must demonstrate conformity with the applicable ISO 27001 requirements for that scope.

The certification process normally includes:

  • Stage 1 audit
  • Stage 2 audit
  • Surveillance audits
  • Recertification

NQA describes the initial certification audit as two mandatory assessment visits and states that certification then remains subject to surveillance activity and later recertification.

The real measure of maturity comes from how effectively the organisation operates and improves its ISMS rather than from achieving a labelled level.

How the Certification Works

The organisation first defines its scope and establishes its ISMS.

It then identifies interested parties and requirements, assesses risks, defines risk treatment, selects controls and builds the Statement of Applicability.

Policies support those controls.

The organisation also needs evidence that its processes operate.

Before external certification, businesses normally complete internal audit activity and management review.

NQA states that organisations pursuing its ISO 27001 certification process need to demonstrate an operational management system that has undergone management review and a full internal audit cycle.

Stage 1 focuses heavily on readiness.

The auditor reviews the management system, scope and key documented information.

Stage 2 looks much more deeply at implementation and effectiveness.

The auditor can interview employees, inspect records, sample controls and compare policy statements against real working practices.

Policies therefore need to survive practical testing.

Every policy should have basic governance information

Whatever policy structure you choose, every controlled policy should normally identify:

  • Policy title
  • Purpose
  • Scope
  • Owner
  • Approver
  • Responsibilities
  • Rules or requirements
  • Related documents
  • Review frequency
  • Current version
  • Approval date

You may also include:

  • Definitions
  • Exceptions
  • Reporting arrangements
  • Compliance responsibilities
  • Relevant controls
  • Related risks

Avoid filling policies with unnecessary text.

Employees need usable documents.

Auditors need controlled documents that match the ISMS.

Management needs clear responsibilities.

Policy ownership matters

Every important policy should have an owner.

The owner should understand the subject and take responsibility for maintaining the document.

For example:

The HR lead might own employee security processes.

The IT lead might own technical access requirements.

The compliance lead might coordinate information security governance.

Senior management should approve the overall Information Security Policy.

Avoid making one person the nominal owner of every document when other people actually operate the processes.

Ownership should reflect reality.

Set sensible policy review periods

Policies should receive review at planned intervals and when significant changes happen.

Do not rely only on annual calendar reminders.

A policy may need earlier review following:

  • A serious security incident
  • Significant technology changes
  • Company restructuring
  • New legal requirements
  • Important new customers
  • Major supplier changes
  • New office locations
  • Changes to working practices
  • Internal audit findings
  • External audit findings
  • New risks

Record the review even when the policy does not require amendment.

That demonstrates active governance.

Policies need evidence behind them

A policy tells an auditor what should happen.

Evidence shows what actually happened.

If your Access Control Policy requires periodic reviews, retain completed review records.

If your Backup Policy requires recovery testing, retain test results.

If your Supplier Security Policy requires due diligence, retain supplier assessments.

If your Incident Management Policy requires lessons learned, retain post-incident reviews.

The strongest ISO 27001 management systems connect policies directly with operational evidence.

Avoid copying generic policies without reviewing them

Template policies can save considerable time.

They can provide structure and remind organisations about important areas.

Problems arise when businesses accept every statement without checking whether it reflects reality.

Imagine a template saying all privileged access receives monthly review when your organisation actually performs reviews every quarter.

The policy immediately creates a commitment that the organisation does not follow.

An auditor can identify the inconsistency.

Adapt templates carefully.

Remove requirements that do not apply.

Add relevant business processes.

Assign real owners.

Match your systems.

Then approve the final policy through your own governance process.

Do not create one policy for every Annex A control

ISO/IEC 27001:2022 contains 93 Annex A controls arranged across four areas. UKAS confirms that the 2022 edition moved from 114 controls to 93, including 11 new controls.

That does not mean an organisation needs 93 policies.

Many controls operate through technical configurations, contracts, processes, records, physical measures or operational procedures.

Several controls can sit under one policy.

One control may also rely on several pieces of evidence.

Design the documentation structure around clarity and effective operation.

Your Statement of Applicability should guide the policy set

The Statement of Applicability, or SoA, provides an important bridge between risk and policies.

For each necessary control, understand:

Why is the control needed?

How have we implemented it?

Who owns it?

Which policy or procedure supports it?

What evidence proves it operates?

If your organisation determines that supplier security controls apply, supporting supplier policies or procedures may become necessary.

If secure development controls do not apply because the organisation performs no relevant development activity, you should not create a large Secure Development Policy merely to fill a folder.

The SoA should help you decide what documentation genuinely adds value.

Cyber risk makes working policies important

The UK Government’s Cyber Security Breaches Survey 2025 to 2026 found that 43 per cent of UK businesses identified a cyber breach or attack during the previous 12 months, representing around 612,000 businesses.

Medium businesses reported a rate of 65 per cent and large businesses 69 per cent.

Phishing remained the most commonly identified attack, affecting 38 per cent of businesses.

The survey also found that only 25 per cent of businesses had a formal incident response plan.

These figures reinforce why policies need to work beyond audit day.

A clear incident policy helps staff act when something happens.

An access policy reduces unnecessary privileges.

A supplier policy helps businesses understand third-party exposure.

A backup policy supports recovery.

The documents matter because the underlying risks are real.

Which UK-based firms offer ISO 27001 consultancy services?

UK organisations can obtain ISO 27001 support from specialist consultants, managed security providers and technology-led compliance services.

When selecting support, look beyond a bundle of policy templates.

A useful service should help connect:

  • Organisational context
  • Stakeholder requirements
  • ISMS scope
  • Security objectives
  • Legal and regulatory requirements
  • Risk assessment
  • Risk acceptance
  • Risk treatment
  • Policies
  • Statement of Applicability
  • Operational controls
  • Evidence
  • Internal audit
  • Management review
  • Corrective actions

UK Cyber Compliance provides ISO 27001 support through its automated and AI-driven platform.

Its current ISO 27001 material describes policy documentation, risk assessment, risk treatment and Statement of Applicability activity as connected parts of the ISMS rather than isolated paperwork.

This can help organisations build policies around their real compliance position rather than maintaining disconnected files.

Make policies accessible to the people who need them

A perfect policy hidden inside a compliance folder does little for information security.

Employees need access to the rules relevant to their work.

That may involve:

  • Staff portals
  • Policy management systems
  • Compliance platforms
  • Employee induction
  • Security awareness sessions
  • Team briefings
  • Policy acknowledgement

Not every employee needs to memorise every policy.

They should understand the requirements relevant to their role and know where to find further information.

Test whether employees understand the policies

An ISO 27001 auditor may interview employees.

They might ask:

How would you report a suspected security incident?

What happens when someone leaves the organisation?

How do you request additional system access?

What should you do with confidential information?

Who should you contact if you lose a company laptop?

Employees do not need scripted answers.

They should demonstrate reasonable awareness.

If nobody can explain the policy, the organisation may need to improve communication or training.

Use one policy where several would create unnecessary complexity

Businesses sometimes create too many documents.

That causes duplication and conflicting requirements.

For example, a smaller organisation could maintain a broad IT Security Policy covering:

  • Acceptable use
  • Access controls
  • Endpoint requirements
  • Authentication
  • Security updates
  • Malware protection
  • Remote working
  • Mobile equipment

Another organisation may prefer separate documents because different teams own each area.

Either approach can work.

Choose the structure that employees can understand and management can maintain.

Keep procedures separate when practical detail becomes complex

Policies normally explain requirements and direction.

Procedures explain how employees carry out activities.

For example:

A policy might state that access must be removed promptly when an employee leaves.

A leaver procedure can explain who notifies IT, who disables accounts, how equipment returns are recorded and who confirms completion.

This separation can help prevent policies from becoming operational manuals.

It also allows teams to update working procedures without repeatedly rewriting high-level policy commitments.

Build a practical policy library

A sensible ISO 27001 policy library for many organisations might include some combination of:

  • Information Security Policy
  • Access Control Policy
  • Acceptable Use Policy
  • Asset Management Policy
  • Information Classification Policy
  • Supplier Security Policy
  • Cloud Security Policy
  • Remote Working Policy
  • Backup Policy
  • Incident Management Policy
  • Vulnerability Management Policy
  • Logging and Monitoring Policy
  • Cryptography Policy
  • Information Transfer Policy
  • Data Retention and Disposal Policy
  • Physical Security Policy
  • Human Resources Security Policy
  • Secure Development Policy
  • Change Management Policy
  • Business Continuity Policy
  • Data Protection Policy

This is not a universal mandatory list.

Your organisation may need fewer.

Another organisation may need additional policies because of its risks, sector, contractual commitments or technology.

Start with the required Information Security Policy, then use your risk assessment and Statement of Applicability to determine what else you genuinely need.

Use automation to keep policies connected to the ISMS

One of the weaknesses of traditional ISO 27001 management comes from storing everything separately.

Policies sit in Word documents.

Risks sit in spreadsheets.

Evidence sits in folders.

Controls live in another worksheet.

Audit actions appear in email.

That makes it difficult to understand how everything connects.

A compliance platform can link policies with risks, controls, owners, evidence and assessment activity.

UK Cyber Compliance uses an automated and AI-driven approach to help organisations manage these relationships while preparing for ISO 27001 certification.

Automation does not remove management responsibility.

Senior leaders still need to approve policies.

Risk owners still need to understand their decisions.

Employees still need to follow security requirements.

The technology should make governance easier rather than replace it.

What should you check before the ISO 27001 audit?

Review each policy and ask:

Is the policy necessary?

Does it match our current organisation?

Does it support relevant risks and controls?

Does it have an owner?

Has management approved it where required?

Is the current version easy to identify?

Has it received review?

Can relevant employees access it?

Do employees understand the important requirements?

Do operational records prove that we follow it?

Does the Statement of Applicability align with it?

Do our technical systems match the claims inside it?

Have significant changes triggered appropriate updates?

If you answer no to several questions, improve the policy before the external assessment.

Policies should make information security easier to manage

ISO 27001 policies have a practical purpose.

The Information Security Policy establishes management direction.

Access rules protect accounts.

Supplier policies help control external risk.

Incident policies tell people how to respond.

Backup requirements support recovery.

Remote working rules protect information outside the office.

Secure development requirements reduce weaknesses in software.

Business continuity requirements support resilience.

Together, these policies help translate the organisation’s risk decisions into everyday behaviour.

The goal should never be to create the largest possible policy library.

Build enough documentation to establish clear rules, support your selected controls and demonstrate that the ISMS operates effectively.

ISO/IEC 27001:2022 provides the framework, but each organisation needs to adapt that framework to its own risks and business circumstances.

UK Cyber Compliance helps businesses make that process more manageable through an automated and AI-driven ISO 27001 platform that connects policies, risks, controls, the Statement of Applicability, evidence and certification preparation.

When policies accurately describe the organisation, employees understand them and evidence proves they work, they become far more than audit documents.

They become part of the way the organisation manages information security every day.

UK Cyber Compliance is here to help

For more information, please do get in touch.

Please check out our Free Cyber Insurance

Other blog posts, Your ISO 27001 Questions AnsweredGet ISO 27001 Certified ,

If you would like to know more, do get in touch as we are happy to answer any questions. Looking to improve your cybersecurity but not sure where to start? Begin by getting certified in Cyber Essentials, the UK government’s scheme that covers all the technical controls that will provide the protection that you need to help guard against criminal attacks.

UK Cyber Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.