Information security policy: the clause the question tests
Whether a written security policy exists, who approved it and when it was last reviewed.
How the customer usually asks it
example"Do you maintain an information security policy approved by management?"
Anchor clauses
3 frameworks| Framework | Anchor clause |
|---|---|
| ISO/IEC 27001:2022 | 5.1 Policies for information security |
| SOC 2 (Trust Services Criteria) | CC5.3 COSO principle 12: Deploys control activities through policies and procedures |
| SIG (Shared Assessments) | domain B Information Security Policy Suite |
Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.
Evidence expected
The approved top-level security policy with its approval record and last review date, and the list of topic policies that sit under it.
The clauses, with what an assessor asks for
ISO 27001 5.1 Policies for information securityWrite, approve and publish a top-level security policy plus topic-specific policies, and review them on a set cadence and after major change.
Where answers usually fall short: Policies not formally approved by senior management; No evidence of distribution or employee acknowledgment
Source: ISO/IEC 27001:2022
SOC 2 CC5.3 COSO principle 12: Deploys control activities through policies and proceduresNamed, not quoted: the criteria text is not held in full here.
Where answers usually fall short: Policy exists with no corresponding procedure, so nothing tells anyone how to perform the control; Procedures performed irregularly with records showing large gaps in the period
Source: SOC 2 (Trust Services Criteria)
SIG domain B Information Security Policy SuiteWhat it asks for, in one line (the standard's own text is not quoted here):
Establish, approve, communicate, and periodically review a suite of information security policies that cover access control, acceptable use, data classification, encryption, vulnerability management, incident response, and supplier management.
Where answers usually fall short: Policies not reviewed annually; Acknowledgement coverage below 95 percent of workforce
Source: SIG (Shared Assessments)