Information security policy and topic-specific policies should be defined, approved by management, published, communicated to, and acknowledged by relevant personnel and interested parties, and reviewed at planned intervals if significant changes occur.
Policies for information security are a vital component of any Information Security Management System. These ensure relevant controls, processes, and procedures are communicated throughout the organisation, providing the system's continuing suitability, adequacy, and effectiveness. Appropriate policies will also ensure the necessary support for information security by business, legal, statutory, regulatory, and contractual requirements.
Organisations seeking to conform to the requirements of this control will need to implement mandatory documented policies of the standard, including, for example, the Information Security Policy, Acceptable Use Policy, Remote Working Policy, and Access Control Policy, as well as various other documented records.
AvISO will be updating and reviewing all the information regularly, so keep us bookmarked and keep checking!
Got a question or need help? Don't hesitate to reach out to our team.
If you would like to know more about ISO Standards, Certification and the value of a good management system you can add to your business we would love to hear from you: Kent: 01892 800476 | London: 02037 458 476 | info@avisoconsultancy.co.uk