Get Demo
↑

ISO 27001 Information Security Policy Template (and the Common Policy Set)

Start with the Clause 5.2 information security policy, then build a common policy set driven by A.5.1 and your SoA — not an invented fixed count.

Published: September 2026 Compliance · ISO 27001 8–12 min read

ISO/IEC 27001:2022 requires an information security policy as documented information under Clause 5.2. It does not mandate a fixed number such as “20 policies.” Most programmes then maintain a common policy set — topic policies selected through risk treatment and Annex A (especially A.5.1 Policies for information security).

Related: Mandatory documents list · SoA · ISO 27001 hub.

Reframe: Soft-search titles still say “20 policies.” Treat that as marketing shorthand. Your SoA and risk register decide which topic policies you actually need.

Top-Level Information Security Policy (5.2)

Draft a short board-approved policy that states purpose, commitment to requirements, continual improvement, and how objectives are set. Publish it internally and make it available to interested parties as appropriate.

Common Policy Set (Examples — Not a Mandated Count)

Add or drop titles based on your SoA — SaaS firms often expand secure development and cloud; OT environments expand physical and safety-adjacent controls.

Build Your ISO 27001 Programme with Continuous Evidence

CyberSilo CSA maps ISMS artefacts and Annex A control evidence; ThreatHawk supports logging and monitoring proof for technological controls.

Frequently Asked Questions

Does ISO 27001 require exactly 20 policies?

No. Clause 5.2 requires an information security policy as documented information. Additional topic policies are chosen based on risk and Annex A needs (often guided by A.5.1).

What must the top-level policy include?

Clause 5.2 requires a policy appropriate to the purpose of the organization, including information security objectives (or a framework for them), commitment to satisfy applicable requirements, and commitment to continual improvement — available as documented information and communicated.

Are templates enough for certification?

Templates accelerate drafting. Auditors look for approved, communicated, implemented policies that match how the organization actually operates.

Mandatory documents · SoA · Annex A.5

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!