An Information Security Policy (Master Policy) that outlines the organization's cybersecurity strategy and serves as a guide for new cybersecurity improvements should be implemented.

Control Type: Administrative

Control Function: Directive

Description: An Information Security Policy is a strategic policy that defines the organization’s cybersecurity objectives and aligns them with overall business objectives and missions. Also known as the Master Cybersecurity Policy, the policy will serve as the single source of truth and direction for developing and improving the information security program. Beneath the master policy, Issue-specific policies and system-specific policies are developed to address business security requirements on more granular levels. Senior management and key stakeholders must be involved in the creation of the Information Security Policy. Agreed upon business objectives and risk tolerance drive the policy. Key stakeholders must thoroughly review the policy before publication. Once finalized, the policy should be published to all stakeholders and integrated into the general policy package distributed to employees. The policy should also be posted to the public through avenues such as the company website. Employees should have easy access to the policy in both print and digital format, and all new hires should become well-versed in the policy as part of their onboarding process.

Points that should be addressed in an Information Security Policy:

  • Overall objectives of the organization’s information security program. Generally, the main objective is to uphold the CIA Triad throughout all business processes and activities. 
  • The acceptable level of risk determined by senior management. 
  • Processes for identifying, reporting, and addressing information security risks. 
  • The connection between information security and business planning. 
  • Roles and responsibilities regarding information security.
  • Map of security controls to risks.
  • Procedures for adapting the entire organization to emerging risks. 
  • Map of risks to key performance metrics and budgetary goals. 
  • The selected key indicators for measuring the effectiveness of the information security program.