[ISO/IEC 27001 Series] - (Requirement 5.2) - Policy -Part 06
- vitormaleite

- Jul 9
- 2 min read

As we defined on the last article, ISMS Scope, now is time to talk about Information Security Policy.
If we search on ISO/IEC 27001 standard, specially on Requirement 5.2 says that Top Management should establish an Information Security Policy that area available as documented information, communicated inside the organization and available to all interested parties. Beyond that, in their structure should:
be aligned to organzational propose;
Include the information security objectives or the entire structural foundation required to achieve them;
Include the commitment to all applicable information security requirements, as well as the continuous improvement of the ISMS.
Therefore, in other words, here we are talking about a High-Level Policy for our ISMS. That is, a document that highlights, in the form of guidelines, the organization’s approach to managing its information security.
To illustrate this, I used the information we established at Viaja Comigo and asked Claude AI to generate a High-Level Policy version, and look at the result:







Obviously, if we critically assess the example generated above, there are improvements to be made, but the message I want to convey is that it is possible to have an Information Security Policy (ISP) in a simple and straightforward way. Well, once it is approved by Top Management, all that remains is to manage it.
Now, of course, this is not the focus of this article, but it is important not to forget that we do not stop only at the ISP. At a lower level, the ISP needs to be supported by Standards and Procedures that also make up the ISMS:
Policy (Guidelines)
What must be done? (More strategic level)
Standards (Rules)
What are the rules? (Tactical level)
Procedures
How to do it? (Operational level)
Until the next requirement! = )

![[ISO/IEC 27001 Series] - (Requirement 4.3) - Determining the scope of ISMS - Part 05](https://static.wixstatic.com/media/01f887_b3c9b5a243494c09b1a7a7729d0f493b~mv2.png/v1/fill/w_917,h_487,al_c,q_90,enc_avif,quality_auto/01f887_b3c9b5a243494c09b1a7a7729d0f493b~mv2.png)
![[ISO/IEC 27001 Series] - (Requirement 4.2) - Understanding the needs and expectations of interested parties - Part 04](https://static.wixstatic.com/media/01f887_041cc95ab21b436cb98e877482ccd2b7~mv2.png/v1/fill/w_980,h_653,al_c,q_90,usm_0.66_1.00_0.01,enc_avif,quality_auto/01f887_041cc95ab21b436cb98e877482ccd2b7~mv2.png)
Comments