Draft the Information Security Policy (ISMS-POL-01)
Scenario
SwiftLend's Scope Statement (Day 5) has been ratified by the Board. Now they need the top-level Information Security Policy — the parent policy that all sub-policies inherit from. It must be readable by the Board (not too technical) but bindingly precise for the ISMS auditor.
Your role
You are drafting ISMS-POL-01 for CEO signature.
Your task
Write the Information Security Policy. Include: 1. Purpose + scope reference 2. Commitment statement (Board + CEO) 3. Guiding principles (5-7 principles like least-privilege, secure-by-default) 4. Roles + responsibilities (Board / CEO / CISO / ISMS Manager / All Staff) 5. Risk-management approach 6. Compliance obligations (RBI, DPDPA, ISO 27001) 7. Continuous improvement commitment 8. Review cycle (annual) + approval line 9. Sign-off block
Deliverable format: Formal 1-page policy document, ~500-900 words
Toolkit
- ISO 27001:2022 Clause 5.2 — Policy requirements
- Board-level tone (no acronyms like SIEM, IDS without expansion first time)
- Include the specific commitment to 'protect Confidentiality, Integrity and Availability'
- Policy owner = CISO. Approver = CEO. Reviewer = Board (annually).
Success criteria (what the AI grades against)
- All 9 sections present
- CEO-signable — no undefined technical jargon
- Explicitly commits to continual improvement
- Cites ISO 27001 + relevant regulations
- Roles are distinct (Board is oversight, CEO is accountable, CISO is executive, ISMS mgr is operational)
- Doesn't ban personal devices without saying how (BYOD policy referenced)
Log in to submit your deliverable for AI review.
Log in / Register