What is an information security policy?
It is a top management-mandated document outlining an organisation’s information security policy, encompassing alignment with organisational goals, incorporation of objectives, commitment to meeting security requirements, and a dedication to continuous improvement, made available as documented information and communicated internally and to relevant stakeholders.
You might also be interested in:
{% icon icon_set="fontawesome-6.4.2" name="Arrow Right" style="SOLID" height="14" purpose="decorative" title="Arrow Right icon" %} Information security policy: Your all-in-one guide
{% icon icon_set="fontawesome-6.4.2" name="Arrow Right" style="SOLID" height="14" purpose="decorative" title="Arrow Right icon" %} ISO 27001 Clause 5.2: Information security policy