Skip to content
arrow_back
search
Annex A 5.1 verified ISO/IEC 27001:2022

Policies for information security

Have clear, approved security policies that everyone knows about and follows.

record_voice_over

Plain language

This control is about having clear rules for protecting information in your organisation. If these rules, known as information security policies, aren't in place, your organisation could be at risk of data breaches, which can lead to financial loss, legal trouble, and damage to your reputation.

Framework

ISO/IEC 27001:2022

Control effect

Preventative

ISO 27001 domain

Organisational controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

19 Mar 2026

Maturity levels

N/A

Official control statement

Information security policy and topic-specific policies shall be defined, approved by management, published, communicated to and acknowledged by relevant personnel and relevant interested parties, and reviewed at planned intervals and if significant changes occur.
verified ISO/IEC 27001:2022 Annex A 5.1
priority_high

Why it matters

If security policies are not defined, approved, communicated and acknowledged, staff lack clear direction, leading to unmanaged risk, inconsistent controls and higher breach likelihood.

settings

Operational notes

Maintain an ISMS policy set: get management approval, publish and brief relevant personnel/parties, record acknowledgement, and review on a schedule and after major changes.

Mapping detail

Mapping

Direction

Controls