Information Security Policy
- Document ID
- PDC-ISP-SAMPLE
- Document version
- 1.0
- Template version
- v1.0.0
- Effective date
- September 27, 2026
- Next review
- September 27, 2027
1. Purpose
This policy establishes the information security program of [Company Name] (the "company"). It sets the rules, responsibilities, and minimum controls the company uses to protect the confidentiality, integrity, and availability of its information and systems, and the information that customers, employees, and partners entrust to it.
Framework. The program is organized around the six functions of the NIST Cybersecurity Framework (CSF) 2.0: Govern, Identify, Protect, Detect, Respond, and Recover. The Safeguards in Implementation Group 1 of the CIS Critical Security Controls v8.1 are treated as the minimum technical baseline.
Relationship to laws and contracts. This policy is designed to help the company meet its legal, regulatory, contractual, and insurance obligations. It does not replace them. Where a law, regulation, contract, or insurance policy sets a stricter requirement, the stricter requirement applies.
Supporting documents. Detailed standards and procedures, such as password, backup, incident response, remote work, and acceptable use rules, support this policy. They must be consistent with it, and the Information Security Officer keeps them current.
2. Scope and Definitions
People. This policy applies to all personnel of [Company Name], and to vendors and service providers whose access to company information assets is governed by contract.
Assets and locations. It covers all information assets owned, leased, licensed, or managed by or for the company, wherever they are located, including offices, plants, jobsites, homes, cloud services, and personally owned devices used for company work.
- Information asset
- Any information the company creates, receives, or holds, in any form, and any hardware, software, cloud service, or account used to store, process, or transmit it.
- Personnel
- Employees, officers, temporary workers, interns, contractors, consultants, and anyone else who uses [Company Name] information assets.
- Privileged account
- An account that can change system settings, security controls, or other users' access, such as a domain, cloud, firewall, or backup administrator account.
- Multi-factor authentication (MFA)
- Sign-in that requires at least two different kinds of proof, such as a password plus an authenticator app, security key, or fingerprint.
- Phishing-resistant MFA
- MFA that cannot be relayed through a fake sign-in page, such as FIDO2 security keys, passkeys, or smart cards.
- Endpoint detection and response (EDR)
- Security software on computers and servers that detects malicious behavior, alerts on it, and can isolate the device.
- Vulnerability
- A weakness in software, hardware, or configuration that an attacker could use to gain access or cause harm.
- Security incident
- An event that actually or potentially compromises the confidentiality, integrity, or availability of an information asset, or that violates this policy.
- Operational technology (OT)
- Systems that monitor or control physical equipment and processes, such as machine controllers, building systems, and industrial sensors.
3. Governance, Roles and Responsibilities
| Role | Responsibilities |
|---|---|
| Executive sponsor (Chief Executive Officer) | Approves this policy and the company risk appetite, provides the resources the program needs, accepts high risks that cannot be reduced, and holds leaders accountable for compliance. |
| Security program lead (Information Security Officer) | Accountable for the information security program. Runs the risk assessment, maintains supporting standards, approves or escalates exceptions, oversees vendors that operate security controls, and reports to the Chief Executive Officer at least quarterly and in a written annual report. |
| Managed IT or security service provider | Operates the security controls it is contracted for, such as patching, endpoint protection, monitoring, and backups, under a written agreement. Reports status, exceptions, and incidents to the Information Security Officer. Accountability for the program stays with the company. |
| Information and system owners | Business managers named for each major system or data set. Classify the information, approve who may access it, and take part in access reviews. |
| Managers | Make sure their teams complete training, request and remove access promptly when roles change, and escalate security needs instead of allowing workarounds. |
| Human resources | Notifies IT of new hires, role changes, and separations before or on the day they happen, and records policy acknowledgments. |
| All personnel | Follow this policy, protect the information they handle, complete training, and report suspected incidents immediately. |
Reporting to leadership. The Information Security Officer gives the Chief Executive Officer a written report at least once a year covering the overall status of the program, the results of the risk assessment and security testing, significant incidents, vendor issues, open exceptions, and recommended changes.
Outsourced operations. Work performed by a service provider must be defined in a written agreement that lists the controls it operates, its response times, how it reports, and how it protects company credentials. The Information Security Officer reviews the provider's performance at least once a year.
Cyber insurance. The Information Security Officer reviews every cyber insurance application and renewal before it is signed to confirm that each answer about security controls is accurate and matches this policy. If a control described on an application is removed or stops working, the Information Security Officer informs the Chief Executive Officer so the company can fix it or update its insurer as the policy terms require.
4. Asset Inventory and Risk Assessment
Asset inventory. The company maintains an inventory of its information assets that is reviewed and updated at least every six months. It records, for each asset, its owner, location, and purpose, and covers:
- Computers, servers, mobile devices, network equipment, printers, and connected devices, including operational technology.
- Installed software and its version, with any software that is no longer supported by its vendor flagged.
- Cloud services and software-as-a-service accounts, including who administers them.
- Where Confidential and Restricted information is stored, and which systems and vendors process it.
Unauthorized devices and software must be removed, blocked, or brought under management promptly. Hardware and software that no longer receive security updates must be replaced or isolated, or covered by an approved exception with compensating controls.
Risk assessment. The Information Security Officer leads a written security risk assessment at least once a year, and again after significant changes such as a new core system, an acquisition, a move to a new site, or a major incident. The assessment identifies reasonably foreseeable internal and external threats, rates their likelihood and impact, evaluates the controls in place, and records the results in a risk register.
Risk treatment. Each risk is reduced with additional controls, avoided, transferred (for example through insurance or contract), or accepted. Only the Chief Executive Officer may accept a high risk, and every acceptance is documented with its reason and a date for review.
5. Data Classification, Handling and Encryption
Information owners classify the information they are responsible for at one of four levels. Information without a label is treated as Internal, and a collection of information takes the highest level of anything it contains.
| Level | Examples | Minimum handling |
|---|---|---|
| Public | Published marketing material, public website content, and press releases. | May be shared freely once approved for release. |
| Internal | Procedures, internal announcements, organization charts, and routine business email. | Kept in company systems and shared only with personnel and authorized vendors. |
| Confidential | Customer and supplier information, contracts, pricing, bids, financial results, engineering drawings, employee records, and anything covered by a confidentiality agreement. | Access limited to those who need it, encrypted on devices and when sent outside the company, and shared externally only under a confidentiality agreement or contract. |
| Restricted | The most sensitive information, including Social Security, driver license, and bank account numbers; and passwords, encryption keys, and other secrets. | Access limited to named roles with MFA, encrypted at rest and in transit at all times, never sent through personal email or stored on personal devices, and access logged where systems allow. |
Encryption at rest. All laptops, desktops, mobile devices, and removable media must use full-disk or device encryption managed by the company, with recovery keys stored in a company-controlled system. Servers, databases, backups, and cloud storage that hold Confidential or Restricted information must be encrypted at rest.
Encryption in transit. Confidential and Restricted information must be sent only over encrypted connections, such as TLS 1.2 or higher, a company VPN, or an encrypted file-sharing or email service. Unencrypted protocols such as FTP and Telnet must not be used for it.
Removable media. Only company-issued, encrypted USB drives and external storage may be used with company information, and personal devices are blocked. Media must be scanned for malware before use, especially before it is connected to production equipment, and lost media must be reported as a security incident.
Retention and disposal. Information is kept only as long as the company record retention requirements, legal holds, and contracts require. Devices and media that held company information must be wiped or destroyed following NIST SP 800-88 media sanitization guidelines before reuse, return, or disposal, and disposal vendors must provide a certificate of destruction. Paper containing Confidential or Restricted information must be shredded.
6. Access Control and Authentication
Least privilege. Access is granted based on job role and business need, with the minimum rights required, and must be approved by the manager and the information owner. Every person uses a unique account; shared accounts are not permitted except where a system cannot support individual accounts and an exception is approved.
Multi-factor authentication. MFA is required for every user and privileged account on every system that supports it, including email, cloud applications, remote access, and business applications. Authenticator apps with number matching, security keys, and passkeys are preferred. Text message and voice codes may be used only where nothing stronger is supported. Personnel must never approve an MFA prompt they did not start, and must report unexpected prompts.
Privileged accounts. Administrators use a separate privileged account for administrative work and a standard account for email and web browsing. Privileged accounts must use phishing-resistant MFA, such as FIDO2 security keys or passkeys. Standard users do not have local administrator rights on their computers. Emergency access accounts are limited in number, protected with strong unique credentials, monitored, and tested at least once a year.
Passwords. Passwords must be long, unique to each system, and never reused between work and personal accounts. Default passwords on all devices and software must be changed before use, and passwords must be stored only in a company-approved password manager. Detailed requirements are set in the company password standard.
Access reviews. Information owners and managers review user access at least every six months, and the Information Security Officer reviews all privileged and service accounts at least every three months. Access no longer needed is removed.
Joiners, movers, and leavers. Access is created only after a request from a manager or human resources. When a person changes roles, access that the new role does not need is removed. When a person leaves, all access, including email, remote access, cloud applications, and building access, must be disabled no later than 24 hours after separation, and at or before the time of notice for an involuntary separation. Company devices and media are collected, and shared passwords the person knew are changed.
Service accounts and remote access. Service and application accounts have a named owner, only the rights they need, and credentials stored in an approved secrets manager or password vault. Remote access to company networks requires a company-approved VPN or zero trust access service with MFA. Remote desktop (RDP) and Windows file sharing (SMB) must never be exposed directly to the internet.
Personnel screening. Before receiving privileged access or access to Restricted information, personnel undergo a background check appropriate to the role, conducted with the notice and consent required by federal and state law.
7. Secure Configuration, Vulnerability and Patch Management
Secure configuration. Computers, servers, network devices, and cloud services are deployed from documented secure configurations, such as the CIS Benchmarks or vendor security baselines, with unnecessary services, accounts, and software removed. Changes to production systems follow a documented change process that includes testing and a way to roll back.
Vulnerability scanning. Automated vulnerability scans of internal and internet-facing systems run at least monthly, and after significant changes. Findings are tracked until they are fixed or covered by an approved exception.
Penetration testing. An independent, qualified tester performs a penetration test of internet-facing systems and the internal network at least once a year and after major changes to internet-facing systems. Findings are fixed within the deadlines below.
Patch deadlines. Security updates for operating systems, applications, browsers, firmware, and network devices are installed automatically wherever possible, and in all cases within the deadlines below. Deadlines run from the date the update is released, or the date the vulnerability is found to be actively exploited, whichever is later. Severity follows the vendor rating or the CVSS base score.
| Severity | Deadline to patch or mitigate |
|---|---|
| Actively exploited (listed in the CISA Known Exploited Vulnerabilities catalog or confirmed exploited) | 7 days |
| Critical (CVSS 9.0 to 10.0) | 14 days |
| High (CVSS 7.0 to 8.9) | 30 days |
| Medium (CVSS 4.0 to 6.9) | 60 days |
| Low (CVSS 0.1 to 3.9) | 90 days |
Internet-facing systems, such as firewalls, VPNs, remote access gateways, and web servers, are patched first. When no patch is available, the vendor-recommended mitigation must be applied within the same deadline, and the system must be isolated or disconnected if the risk cannot otherwise be reduced.
Systems that cannot be patched. Some systems, such as production equipment controllers or software certified by a vendor for a specific version, cannot be patched on this schedule. Each one must be listed in the asset inventory with its owner and compensating controls, such as network segmentation, restricted access, and additional monitoring, and approved as an exception by the Information Security Officer.
8. Endpoint, Email and Network Security
Endpoint protection. Every company computer and server runs company-approved endpoint detection and response (EDR) software with tamper protection turned on. Alerts are monitored 24 hours a day, 7 days a week by a managed detection and response service or security operations center that is authorized to isolate a compromised device immediately. Devices without working protection are blocked from company resources until fixed.
Device management. Computers and mobile devices that access company information must be enrolled in company device management, lock automatically after no more than 15 minutes of inactivity, and be able to be located, locked, or wiped remotely. Use of personally owned devices is governed by the company remote work and personal device rules.
Email security. Company email is filtered for spam, malware, phishing, and impersonation, and messages from outside the company are clearly marked. SPF, DKIM, and DMARC are published for every company email domain, with DMARC set to quarantine or reject so that email faking the company domain is not delivered. Automatic forwarding of company email to outside addresses is disabled.
Payment and banking changes. Any request to send money, pay a new account, or change banking or payment details must be verified by calling a known phone number on file, never one supplied in the request, before it is acted on.
Web filtering. Company devices use DNS or web filtering that blocks known malicious, phishing, and newly registered domains, on and off the company network.
Network security. Company networks are protected by firewalls that deny inbound traffic by default and are updated and backed up. Servers, operational technology, cameras and other connected devices, and guest Wi-Fi are placed on separate network segments. Wireless networks use WPA2-Enterprise, WPA3, or stronger, and management interfaces of network devices are not reachable from the internet.
9. Logging and Monitoring
Log collection. Security logs are collected in a central location from at least the identity and sign-in system, email, firewalls and VPNs, EDR, servers, cloud administration consoles, and backup systems. System clocks are synchronized to a trusted time source so events can be correlated.
Retention and protection. Logs are kept for at least 12 months, or longer where a law, contract, or legal hold requires. Access to logs is limited, and logs are protected from alteration and deletion.
Alerting. The monitoring service reviews alerts continuously and escalates confirmed threats immediately. At a minimum, alerts are configured for:
- Repeated failed sign-ins, sign-ins from unusual locations, and bursts of MFA prompts.
- Creation of new privileged accounts or changes to administrator groups.
- New email forwarding or inbox rules that move or delete messages.
- Security tools being disabled, logs being cleared, or backups being deleted.
- Large or unusual data transfers and mass file changes that may indicate ransomware.
10. Incident Response, Backup and Recovery
Report immediately. Personnel must report a suspected security incident, such as a clicked phishing link, a lost device, a ransom note, or unexpected MFA prompts, to the Information Security Officer immediately. Report even if you are unsure and even if you made a mistake; no one faces retaliation for a good-faith report. Do not turn off, wipe, or try to fix an affected device unless told to, because that can destroy evidence.
Response. Incidents are handled under the company incident response plan, which names the response team and its contacts, how incidents are classified and escalated, and how they are contained, investigated, recovered from, and reviewed afterward. The plan is tested with a tabletop exercise at least once a year. Legal counsel assesses every incident that may involve personal, regulated, or customer information for notification obligations under law and contract, and the Information Security Officer records lessons learned and changes to controls.
Insurer notice. The incident response plan lists the cyber insurer's claim or breach hotline. The Information Security Officer notifies the insurer as the policy requires, and before engaging outside incident response firms, forensic investigators, or legal counsel, because many policies require the use of insurer-approved vendors to preserve coverage.
Backup and recovery. Critical systems and data are backed up automatically, with at least one copy kept offline or immutable so it cannot be changed or deleted by ransomware or a compromised administrator account. Backup systems require MFA and separate credentials. Restores are tested at least quarterly, and recovery time and recovery point objectives for critical systems are documented and approved by the business. Detailed requirements are set in the company data backup and recovery rules.
11. Vendor and Third-Party Risk
Vendors that store or process Confidential or Restricted information, or that can connect to company systems, including IT and security providers, software vendors with remote support access, and cloud services, are critical vendors. The Information Security Officer keeps a list of critical vendors and the information and systems each can reach.
Assessment. Before a contract is signed, and at least once a year after that, each critical vendor is assessed in proportion to its access. The assessment reviews:
- Independent security reports, such as a SOC 2 Type II report or ISO/IEC 27001 certificate, or a completed security questionnaire.
- MFA, encryption, and how the vendor controls its own staff access to company information.
- Incident history, breach notification commitments, and cyber insurance.
- Where information is stored, which subcontractors are used, and how information is returned or deleted at the end of the contract.
Contract terms. Contracts with critical vendors must require appropriate security controls, confidentiality, prompt notice of security incidents affecting company information, cooperation with investigations, and return or deletion of company information when the contract ends.
Vendor access. Vendor accounts are individual, protected with MFA, limited to the systems needed, and enabled only while work is performed where practical. Vendor remote access sessions are logged, and vendor access is removed when the contract ends.
12. Physical and Environmental Security
- Server rooms, network closets, and equipment cabinets are locked, with access limited to authorized personnel and reviewed when access lists change.
- Visitors sign in, are escorted in areas where Confidential information is visible or systems are housed, and do not connect devices to the company network except guest Wi-Fi.
- Critical equipment is protected by uninterruptible power, appropriate cooling, and fire protection suited to electronic equipment.
- Screens are locked when unattended, and Confidential and Restricted papers are not left on desks, printers, or in vehicles.
- Laptops and mobile devices are never left unattended in public places or visible in vehicles, and a lost or stolen device is reported immediately.
13. Security Awareness Training
All personnel complete security awareness training within 30 days of starting, and before receiving access to Restricted information, and again at least once a year. Training covers:
- This policy and how to report incidents.
- Recognizing phishing, business email compromise, fake invoices, and phone and text scams, including AI-generated voice and video impersonation.
- MFA, password managers, and never approving an unexpected sign-in prompt.
- Handling Confidential and Restricted information and using approved systems only.
- Safe use of devices at home, while traveling, and on public networks.
Phishing simulations. Simulated phishing tests are sent to all personnel with email at least monthly. People who fall for a simulation receive short follow-up training. Simulations are a learning tool: a failed test alone does not lead to discipline, but repeated disregard of training may be addressed under the enforcement section.
Role-based training. Administrators, developers, finance and payroll staff, and executives receive additional training suited to the risks of their roles. Training completion is recorded and reported to the Information Security Officer.
14. Legal, Regulatory and Contractual Requirements
[Company Name] identifies the laws, regulations, contracts, and insurance terms that apply to the information it holds, and the Information Security Officer confirms the program meets them. The following requirements apply in addition to the rest of this policy:
Personal information. Personal information is protected and breaches are handled under applicable state privacy, data security, and breach notification laws, including those of North Carolina and of every state where affected individuals live. Some states, such as Massachusetts under 201 CMR 17.00, require a written information security program from any business that owns or licenses personal information about their residents.
Contracts and insurance. Security requirements in customer contracts, supplier agreements, and insurance policies are recorded when the agreement is signed and built into the controls in this policy. Answers to customer security questionnaires and insurance applications must be accurate and consistent with this policy.
Related standards. This policy is designed to align with:
- NIST Cybersecurity Framework (CSF) 2.0.
- CIS Critical Security Controls v8.1, Implementation Group 1.
- NIST SP 800-88, Guidelines for Media Sanitization.
15. Compliance, Exceptions and Enforcement
Monitoring compliance. The Information Security Officer checks compliance with this policy through automated reports, access reviews, vulnerability scans, training records, and at least one internal review a year. Company systems and accounts may be monitored for security and compliance purposes, in line with applicable law, and personnel should have no expectation of privacy in company systems beyond what the law provides.
Exceptions. Where a requirement cannot be met, a written exception request must be sent to the Information Security Officer, explaining the business need, the risk, the compensating controls, and the date by which the requirement will be met. The Information Security Officer may approve low and moderate risk exceptions; exceptions that create high risk or involve regulated information require approval by the Chief Executive Officer. Exceptions are recorded, limited to no more than 12 months, and reviewed before renewal. No exception may permit something a law or contract prohibits.
Enforcement. Violations of this policy may result in loss of access and disciplinary action, up to and including termination of employment or of a contractor or vendor agreement, consistent with applicable law. Prompt self-reporting of a mistake is taken into account. Deliberately bypassing a security control, or failing to report a known incident, is a serious violation.
Policy review. The Information Security Officer reviews this policy no later than September 27, 2027, and sooner after a significant incident, a major change to systems or the business, or a new legal, contract, or insurance requirement. Changes are approved by the Chief Executive Officer and communicated to personnel.
16. Acknowledgment
I have read and understand the [Company Name] Information Security Policy. I agree to protect company and customer information, to use only approved systems and accounts, to complete required training, and to report suspected security incidents immediately. I understand that company systems may be monitored and that violations may result in disciplinary action.
Name
Job title
Signature
Date
17. Document Control and Revision History
| Field | Value |
|---|---|
| Document | Information Security Policy |
| Organization | [Company Name] |
| Document ID | PDC-ISP-SAMPLE |
| Document version | 1.0 |
| Effective date | September 27, 2026 |
| Next scheduled review | September 27, 2027 |
| Policy owner | Information Security Officer |
| Approved by | Chief Executive Officer |
| Source template | Preferred Data Corporation Information Security Policy template v1.0.0 |
Revision history. Record every change to this policy below. Increase the document version and obtain approval again each time the policy is revised.
| Version | Date | Description of change | Approved by |
|---|---|---|---|
| 1.0 | September 27, 2026 | Initial adoption, generated from template v1.0.0. | Chief Executive Officer |
| Blank | Blank | Blank | Blank |
| Blank | Blank | Blank | Blank |
18. Template Notice and Legal Disclaimer
This document was generated from a starter template provided by Preferred Data Corporation. It is general information only. It is not legal advice and it is not a substitute for advice from a licensed attorney.
Preferred Data Corporation is not a law firm. It makes no representation that this document is complete, current, or suitable for any particular organization, industry, jurisdiction, or regulatory requirement, and it is not responsible or liable for any use of this template or of any policy created from it. You are solely responsible for how you adapt, adopt, and enforce it.
Laws, regulations, insurance requirements, and contracts that apply to your organization may require different or additional terms. Before you adopt, publish, or rely on this policy, and in every case where you have a legal, regulatory, or contractual obligation, have it reviewed by qualified legal counsel.