Security Questionnaire Mapper
Governance and policy ยท question family

Information security policy: the clause the question tests

Whether a written security policy exists, who approved it and when it was last reviewed.

How the customer usually asks it

example

"Do you maintain an information security policy approved by management?"

Read this question

Anchor clauses

3 frameworks
FrameworkAnchor clause
ISO/IEC 27001:20225.1 Policies for information security
SOC 2 (Trust Services Criteria)CC5.3 COSO principle 12: Deploys control activities through policies and procedures
SIG (Shared Assessments)domain B Information Security Policy Suite

Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.

Evidence expected

The approved top-level security policy with its approval record and last review date, and the list of topic policies that sit under it.

The clauses, with what an assessor asks for

ISO 27001 5.1 Policies for information security

Write, approve and publish a top-level security policy plus topic-specific policies, and review them on a set cadence and after major change.

Evidence an assessor expects: Security policy document; Policy approval records; Policy distribution log; Policy review schedule; Policy change records
Where answers usually fall short: Policies not formally approved by senior management; No evidence of distribution or employee acknowledgment
Source: ISO/IEC 27001:2022
SOC 2 CC5.3 COSO principle 12: Deploys control activities through policies and procedures

Named, not quoted: the criteria text is not held in full here.

Evidence an assessor expects: Policies establishing what is expected and the procedures putting them into action, with owners and approval evidence; Evidence responsibility and accountability for executing each procedure is established with competent personnel; Evidence procedures are performed timely, with records showing when each was performed during the period; Evidence corrective action is taken where a procedure identifies an issue; Evidence policies and procedures are reassessed periodically and updated as needed
Where answers usually fall short: Policy exists with no corresponding procedure, so nothing tells anyone how to perform the control; Procedures performed irregularly with records showing large gaps in the period
Source: SOC 2 (Trust Services Criteria)
SIG domain B Information Security Policy Suite

What it asks for, in one line (the standard's own text is not quoted here):

Establish, approve, communicate, and periodically review a suite of information security policies that cover access control, acceptable use, data classification, encryption, vulnerability management, incident response, and supplier management.

Evidence an assessor expects: Approved policy library with version control; Executive or board approval records; Distribution and acknowledgement logs; Annual review evidence
Where answers usually fall short: Policies not reviewed annually; Acknowledgement coverage below 95 percent of workforce
Source: SIG (Shared Assessments)

Other families in governance and policy