Description
The template is flexibly customisable and contains standard market specifications in the areas:
- Guidelines for the management
- Organisation of information security
- Personnel security
- Management of values/assets
- Access control, cryptography
- physical and environmental security
- the full chapter of operational security
- communication security
- acquisition/development/maintenance of systems
- supplier relations
- Information security incident management
- Information security aspects of business continuity management
- as well as the area of compliance
All areas are prefaced by a definition of the primary target group responsible for implementing the requirements of that area. With this method, the information security policy can be implemented in a targeted manner by involving the relevant departments quickly and easily in the company.
The template Information Security Policy according to ISO 27001 was developed especially for small and medium-sized enterprises and deliberately avoids splitting the requirements into individual documents, such as a separate cryptography policy. All requirements concerning users are not included in this template, but in the package template user policy according to ISO 27001, so companies do not have to train their users on the central information security policy.
Language: German / English
Licence: Digital template in Microsoft Office format with right of use for one company. The template may be modified as desired. No resale, redistribution or commercial use by consulting firms is permitted.