Day 6 of 22ISMS · ISO 27001· ~60 min

Draft the Information Security Policy (ISMS-POL-01)

Scenario

SwiftLend's Scope Statement (Day 5) has been ratified by the Board. Now they need the top-level Information Security Policy — the parent policy that all sub-policies inherit from. It must be readable by the Board (not too technical) but bindingly precise for the ISMS auditor.

Your role

You are drafting ISMS-POL-01 for CEO signature.

Your task

Write the Information Security Policy. Include: 1. Purpose + scope reference 2. Commitment statement (Board + CEO) 3. Guiding principles (5-7 principles like least-privilege, secure-by-default) 4. Roles + responsibilities (Board / CEO / CISO / ISMS Manager / All Staff) 5. Risk-management approach 6. Compliance obligations (RBI, DPDPA, ISO 27001) 7. Continuous improvement commitment 8. Review cycle (annual) + approval line 9. Sign-off block

Deliverable format: Formal 1-page policy document, ~500-900 words

Toolkit

  • ISO 27001:2022 Clause 5.2 — Policy requirements
  • Board-level tone (no acronyms like SIEM, IDS without expansion first time)
  • Include the specific commitment to 'protect Confidentiality, Integrity and Availability'
  • Policy owner = CISO. Approver = CEO. Reviewer = Board (annually).

Success criteria (what the AI grades against)

  • All 9 sections present
  • CEO-signable — no undefined technical jargon
  • Explicitly commits to continual improvement
  • Cites ISO 27001 + relevant regulations
  • Roles are distinct (Board is oversight, CEO is accountable, CISO is executive, ISMS mgr is operational)
  • Doesn't ban personal devices without saying how (BYOD policy referenced)

Log in to submit your deliverable for AI review.

Log in / Register