Home / ISO 27001 Glossary of Terms / Policies for Information Security

Policies for Information Security

18/09/2025

Author: Stuart Barker | ISO 27001 Expert and Thought Leader

ISO 27001 Policies for Information Security is the ISO 27001 control called ISO 27001:2022 Annex A 5.1: Policies for Information Security. This control is about having clear rules for keeping company information safe. Think of these rules as a guidebook for everyone in the company. The goal is to make sure everyone knows what to do to protect important information from being lost or stolen.

Examples

  • Policy on Access Control: A rule that says only certain people can see specific files or data. For example, a rule might say only the payroll team can see employee salary information.
  • Policy on Data Handling: A guide on how to handle different types of information. It could explain how to properly save, share, and delete files to keep them safe.
  • Acceptable Use Policy: This policy explains how employees can use company computers and networks. It might say, for example, that employees should not use company devices for personal shopping or games.
  • Clear Desk and Clear Screen Policy: This is a simple rule that helps prevent others from seeing sensitive information. It says that employees should lock their computers when they leave their desk and put away any papers with important information.

Context

Having these policies in place is a key part of information security. These policies provide a framework to ensure that information security management system (ISMS) goals are met. They help make sure everyone in the company knows their role in protecting information. Without these policies, it would be hard to make sure everyone is following the same rules. The policies are also needed to show auditors and partners that a company is serious about keeping its information safe. They are the foundation of any good security program.

Relevant ISO 27001 Controls

The following controls from the ISO/IEC 27001:2022 standard are related to Policies for Information Security:

ISO 27001:2022 Annex A 5.1: Policies for Information Security: the main ISO 27001 control for the requirement for ISO 27001 policies.

ISO 27001:2022 Annex A 5.36 Compliance With Policies, Rules And Standards For Information Security: the requirement to be compliant with policies.

ISO 27001 Annex A 6.3: Information Security Awareness Education and Training: This control ensures that everyone knows the policies. It’s not enough to just have a policy; you need to make sure everyone understands it.

ISO 27001 Annex A 6.4: Disciplinary Process: This control is about what happens if a policy is not followed. The policies define the rules, and this control defines the consequences for breaking them.

About the author

Stuart Barker is an information security practitioner of over 30 years. He holds an MSc in Software and Systems Security and an undergraduate degree in Software Engineering. He is an ISO 27001 expert and thought leader holding both ISO 27001 Lead Implementer and ISO 27001 Lead Auditor qualifications. In 2010 he started his first cyber security consulting business that he sold in 2018. He worked for over a decade for GE, leading a data governance team across Europe and since then has gone on to deliver hundreds of client engagements and audits.

He regularly mentors and trains professionals on information security and runs a successful ISO 27001 YouTube channel where he shows people how they can implement ISO 27001 themselves. He is passionate that knowledge should not be hoarded and brought to market the first of its kind online ISO 27001 store for all the tools and templates people need when they want to do it themselves.

In his personal life he is an active and a hobbyist kickboxer.

His specialisms are ISO 27001 and SOC 2 and his niche is start up and early stage business.