Free cybersecurity policy template

Free Information Security Policy Template and Generator

An information security policy, often called a written information security program (WISP), is the executive-approved rulebook for how a business protects its systems and data: who is accountable, how data is classified, who gets access, how fast patches go in, and how vendors are vetted. Cyber insurers, auditors and customers now ask for one, and smaller firms are prime targets: Verizon's 2025 Data Breach Investigations Report found ransomware present in 88% of breaches at small and mid-sized organizations. This free generator builds a policy aligned to NIST CSF 2.0 and CIS Controls IG1 in a few minutes.

An information security policy is a formal, executive-approved document that sets the rules, roles and minimum controls an organization uses to protect the confidentiality, integrity and availability of its information and systems.

Template version
v1.0.0
Last reviewed
September 27, 2026
Sections
18
Guided phases
6
Time to complete
About 6 minutes
Price
Free

Why does this policy matter now?

What is inside the Information Security Policy template?

18 sections, ending with the document control table and the legal notice every template carries. Select any section to jump to it in the sample below.

  1. 1. PurposeWhy the program exists, the frameworks it follows, and how it relates to laws and contracts.
  2. 2. Scope and DefinitionsWho and what the policy covers, with plain-language definitions of key terms.
  3. 3. Governance, Roles and ResponsibilitiesWho is accountable for security, who does the work, and how leadership stays informed.
  4. 4. Asset Inventory and Risk AssessmentKeeping a current inventory of hardware, software and data, and assessing risk on a schedule.
  5. 5. Data Classification, Handling and EncryptionFour classification levels with handling rules, encryption at rest and in transit, and secure disposal.
  6. 6. Access Control and AuthenticationLeast privilege, MFA, administrator accounts, access reviews, and fast removal of access.
  7. 7. Secure Configuration, Vulnerability and Patch ManagementSecure baselines, scanning, severity-based patch deadlines, and handling systems that cannot be patched.
  8. 8. Endpoint, Email and Network SecurityEDR and monitoring, email authentication and filtering, web filtering, firewalls and segmentation.
  9. 9. Logging and MonitoringWhich logs are collected, how long they are kept, and which events raise alerts.
  10. 10. Incident Response, Backup and RecoveryHow incidents are reported and handled, regulatory deadlines, and resilient backups.
  11. 11. Vendor and Third-Party RiskAssessing, contracting with and monitoring vendors that hold data or can reach company systems.
  12. 12. Physical and Environmental SecurityProtecting server rooms, network closets, devices, paper records and visitors.
  13. 13. Security Awareness TrainingTraining at onboarding and on a schedule, phishing simulations, and role-based training.
  14. 14. Legal, Regulatory and Contractual RequirementsAdded requirements for personal, health, payment, financial and defense information, and related standards.
  15. 15. Compliance, Exceptions and EnforcementMonitoring compliance, how exceptions are approved, consequences for violations, and policy review.
  16. 16. AcknowledgmentA signature block confirming each person has read and will follow the policy.
  17. 17. Document Control and Revision HistoryDocument ID, version, effective date, next review, owner and approver, plus a revision history table.
  18. 18. Template Notice and Legal DisclaimerThe starter-template disclaimer and the reminder to have qualified counsel review the policy.
Template changelog
  • v1.0.0, September 27, 2026

    • Initial release aligned to NIST CSF 2.0 and CIS Critical Security Controls v8.1 Implementation Group 1, with conditional requirements for the HIPAA Security Rule, CMMC and NIST SP 800-171, PCI DSS v4.0.1 and the FTC Safeguards Rule.

Read the full sample Information Security Policy

This sample uses the recommended answer to every question and a placeholder company name. Build your own version to put in your organization's name, owners and choices.

Sections in this policy
Sample[Company Name]

Information Security Policy

Document ID
PDC-ISP-SAMPLE
Document version
1.0
Template version
v1.0.0
Effective date
September 27, 2026
Next review
September 27, 2027

1. Purpose

This policy establishes the information security program of [Company Name] (the "company"). It sets the rules, responsibilities, and minimum controls the company uses to protect the confidentiality, integrity, and availability of its information and systems, and the information that customers, employees, and partners entrust to it.

Framework. The program is organized around the six functions of the NIST Cybersecurity Framework (CSF) 2.0: Govern, Identify, Protect, Detect, Respond, and Recover. The Safeguards in Implementation Group 1 of the CIS Critical Security Controls v8.1 are treated as the minimum technical baseline.

Relationship to laws and contracts. This policy is designed to help the company meet its legal, regulatory, contractual, and insurance obligations. It does not replace them. Where a law, regulation, contract, or insurance policy sets a stricter requirement, the stricter requirement applies.

Supporting documents. Detailed standards and procedures, such as password, backup, incident response, remote work, and acceptable use rules, support this policy. They must be consistent with it, and the Information Security Officer keeps them current.

2. Scope and Definitions

People. This policy applies to all personnel of [Company Name], and to vendors and service providers whose access to company information assets is governed by contract.

Assets and locations. It covers all information assets owned, leased, licensed, or managed by or for the company, wherever they are located, including offices, plants, jobsites, homes, cloud services, and personally owned devices used for company work.

Information asset
Any information the company creates, receives, or holds, in any form, and any hardware, software, cloud service, or account used to store, process, or transmit it.
Personnel
Employees, officers, temporary workers, interns, contractors, consultants, and anyone else who uses [Company Name] information assets.
Privileged account
An account that can change system settings, security controls, or other users' access, such as a domain, cloud, firewall, or backup administrator account.
Multi-factor authentication (MFA)
Sign-in that requires at least two different kinds of proof, such as a password plus an authenticator app, security key, or fingerprint.
Phishing-resistant MFA
MFA that cannot be relayed through a fake sign-in page, such as FIDO2 security keys, passkeys, or smart cards.
Endpoint detection and response (EDR)
Security software on computers and servers that detects malicious behavior, alerts on it, and can isolate the device.
Vulnerability
A weakness in software, hardware, or configuration that an attacker could use to gain access or cause harm.
Security incident
An event that actually or potentially compromises the confidentiality, integrity, or availability of an information asset, or that violates this policy.
Operational technology (OT)
Systems that monitor or control physical equipment and processes, such as machine controllers, building systems, and industrial sensors.

3. Governance, Roles and Responsibilities

RoleResponsibilities
Executive sponsor (Chief Executive Officer)Approves this policy and the company risk appetite, provides the resources the program needs, accepts high risks that cannot be reduced, and holds leaders accountable for compliance.
Security program lead (Information Security Officer)Accountable for the information security program. Runs the risk assessment, maintains supporting standards, approves or escalates exceptions, oversees vendors that operate security controls, and reports to the Chief Executive Officer at least quarterly and in a written annual report.
Managed IT or security service providerOperates the security controls it is contracted for, such as patching, endpoint protection, monitoring, and backups, under a written agreement. Reports status, exceptions, and incidents to the Information Security Officer. Accountability for the program stays with the company.
Information and system ownersBusiness managers named for each major system or data set. Classify the information, approve who may access it, and take part in access reviews.
ManagersMake sure their teams complete training, request and remove access promptly when roles change, and escalate security needs instead of allowing workarounds.
Human resourcesNotifies IT of new hires, role changes, and separations before or on the day they happen, and records policy acknowledgments.
All personnelFollow this policy, protect the information they handle, complete training, and report suspected incidents immediately.

Reporting to leadership. The Information Security Officer gives the Chief Executive Officer a written report at least once a year covering the overall status of the program, the results of the risk assessment and security testing, significant incidents, vendor issues, open exceptions, and recommended changes.

Outsourced operations. Work performed by a service provider must be defined in a written agreement that lists the controls it operates, its response times, how it reports, and how it protects company credentials. The Information Security Officer reviews the provider's performance at least once a year.

Cyber insurance. The Information Security Officer reviews every cyber insurance application and renewal before it is signed to confirm that each answer about security controls is accurate and matches this policy. If a control described on an application is removed or stops working, the Information Security Officer informs the Chief Executive Officer so the company can fix it or update its insurer as the policy terms require.

4. Asset Inventory and Risk Assessment

Asset inventory. The company maintains an inventory of its information assets that is reviewed and updated at least every six months. It records, for each asset, its owner, location, and purpose, and covers:

  • Computers, servers, mobile devices, network equipment, printers, and connected devices, including operational technology.
  • Installed software and its version, with any software that is no longer supported by its vendor flagged.
  • Cloud services and software-as-a-service accounts, including who administers them.
  • Where Confidential and Restricted information is stored, and which systems and vendors process it.

Unauthorized devices and software must be removed, blocked, or brought under management promptly. Hardware and software that no longer receive security updates must be replaced or isolated, or covered by an approved exception with compensating controls.

Risk assessment. The Information Security Officer leads a written security risk assessment at least once a year, and again after significant changes such as a new core system, an acquisition, a move to a new site, or a major incident. The assessment identifies reasonably foreseeable internal and external threats, rates their likelihood and impact, evaluates the controls in place, and records the results in a risk register.

Risk treatment. Each risk is reduced with additional controls, avoided, transferred (for example through insurance or contract), or accepted. Only the Chief Executive Officer may accept a high risk, and every acceptance is documented with its reason and a date for review.

5. Data Classification, Handling and Encryption

Information owners classify the information they are responsible for at one of four levels. Information without a label is treated as Internal, and a collection of information takes the highest level of anything it contains.

LevelExamplesMinimum handling
PublicPublished marketing material, public website content, and press releases.May be shared freely once approved for release.
InternalProcedures, internal announcements, organization charts, and routine business email.Kept in company systems and shared only with personnel and authorized vendors.
ConfidentialCustomer and supplier information, contracts, pricing, bids, financial results, engineering drawings, employee records, and anything covered by a confidentiality agreement.Access limited to those who need it, encrypted on devices and when sent outside the company, and shared externally only under a confidentiality agreement or contract.
RestrictedThe most sensitive information, including Social Security, driver license, and bank account numbers; and passwords, encryption keys, and other secrets.Access limited to named roles with MFA, encrypted at rest and in transit at all times, never sent through personal email or stored on personal devices, and access logged where systems allow.

Encryption at rest. All laptops, desktops, mobile devices, and removable media must use full-disk or device encryption managed by the company, with recovery keys stored in a company-controlled system. Servers, databases, backups, and cloud storage that hold Confidential or Restricted information must be encrypted at rest.

Encryption in transit. Confidential and Restricted information must be sent only over encrypted connections, such as TLS 1.2 or higher, a company VPN, or an encrypted file-sharing or email service. Unencrypted protocols such as FTP and Telnet must not be used for it.

Removable media. Only company-issued, encrypted USB drives and external storage may be used with company information, and personal devices are blocked. Media must be scanned for malware before use, especially before it is connected to production equipment, and lost media must be reported as a security incident.

Retention and disposal. Information is kept only as long as the company record retention requirements, legal holds, and contracts require. Devices and media that held company information must be wiped or destroyed following NIST SP 800-88 media sanitization guidelines before reuse, return, or disposal, and disposal vendors must provide a certificate of destruction. Paper containing Confidential or Restricted information must be shredded.

6. Access Control and Authentication

Least privilege. Access is granted based on job role and business need, with the minimum rights required, and must be approved by the manager and the information owner. Every person uses a unique account; shared accounts are not permitted except where a system cannot support individual accounts and an exception is approved.

Multi-factor authentication. MFA is required for every user and privileged account on every system that supports it, including email, cloud applications, remote access, and business applications. Authenticator apps with number matching, security keys, and passkeys are preferred. Text message and voice codes may be used only where nothing stronger is supported. Personnel must never approve an MFA prompt they did not start, and must report unexpected prompts.

Privileged accounts. Administrators use a separate privileged account for administrative work and a standard account for email and web browsing. Privileged accounts must use phishing-resistant MFA, such as FIDO2 security keys or passkeys. Standard users do not have local administrator rights on their computers. Emergency access accounts are limited in number, protected with strong unique credentials, monitored, and tested at least once a year.

Passwords. Passwords must be long, unique to each system, and never reused between work and personal accounts. Default passwords on all devices and software must be changed before use, and passwords must be stored only in a company-approved password manager. Detailed requirements are set in the company password standard.

Access reviews. Information owners and managers review user access at least every six months, and the Information Security Officer reviews all privileged and service accounts at least every three months. Access no longer needed is removed.

Joiners, movers, and leavers. Access is created only after a request from a manager or human resources. When a person changes roles, access that the new role does not need is removed. When a person leaves, all access, including email, remote access, cloud applications, and building access, must be disabled no later than 24 hours after separation, and at or before the time of notice for an involuntary separation. Company devices and media are collected, and shared passwords the person knew are changed.

Service accounts and remote access. Service and application accounts have a named owner, only the rights they need, and credentials stored in an approved secrets manager or password vault. Remote access to company networks requires a company-approved VPN or zero trust access service with MFA. Remote desktop (RDP) and Windows file sharing (SMB) must never be exposed directly to the internet.

Personnel screening. Before receiving privileged access or access to Restricted information, personnel undergo a background check appropriate to the role, conducted with the notice and consent required by federal and state law.

7. Secure Configuration, Vulnerability and Patch Management

Secure configuration. Computers, servers, network devices, and cloud services are deployed from documented secure configurations, such as the CIS Benchmarks or vendor security baselines, with unnecessary services, accounts, and software removed. Changes to production systems follow a documented change process that includes testing and a way to roll back.

Vulnerability scanning. Automated vulnerability scans of internal and internet-facing systems run at least monthly, and after significant changes. Findings are tracked until they are fixed or covered by an approved exception.

Penetration testing. An independent, qualified tester performs a penetration test of internet-facing systems and the internal network at least once a year and after major changes to internet-facing systems. Findings are fixed within the deadlines below.

Patch deadlines. Security updates for operating systems, applications, browsers, firmware, and network devices are installed automatically wherever possible, and in all cases within the deadlines below. Deadlines run from the date the update is released, or the date the vulnerability is found to be actively exploited, whichever is later. Severity follows the vendor rating or the CVSS base score.

SeverityDeadline to patch or mitigate
Actively exploited (listed in the CISA Known Exploited Vulnerabilities catalog or confirmed exploited)7 days
Critical (CVSS 9.0 to 10.0)14 days
High (CVSS 7.0 to 8.9)30 days
Medium (CVSS 4.0 to 6.9)60 days
Low (CVSS 0.1 to 3.9)90 days

Internet-facing systems, such as firewalls, VPNs, remote access gateways, and web servers, are patched first. When no patch is available, the vendor-recommended mitigation must be applied within the same deadline, and the system must be isolated or disconnected if the risk cannot otherwise be reduced.

Systems that cannot be patched. Some systems, such as production equipment controllers or software certified by a vendor for a specific version, cannot be patched on this schedule. Each one must be listed in the asset inventory with its owner and compensating controls, such as network segmentation, restricted access, and additional monitoring, and approved as an exception by the Information Security Officer.

8. Endpoint, Email and Network Security

Endpoint protection. Every company computer and server runs company-approved endpoint detection and response (EDR) software with tamper protection turned on. Alerts are monitored 24 hours a day, 7 days a week by a managed detection and response service or security operations center that is authorized to isolate a compromised device immediately. Devices without working protection are blocked from company resources until fixed.

Device management. Computers and mobile devices that access company information must be enrolled in company device management, lock automatically after no more than 15 minutes of inactivity, and be able to be located, locked, or wiped remotely. Use of personally owned devices is governed by the company remote work and personal device rules.

Email security. Company email is filtered for spam, malware, phishing, and impersonation, and messages from outside the company are clearly marked. SPF, DKIM, and DMARC are published for every company email domain, with DMARC set to quarantine or reject so that email faking the company domain is not delivered. Automatic forwarding of company email to outside addresses is disabled.

Payment and banking changes. Any request to send money, pay a new account, or change banking or payment details must be verified by calling a known phone number on file, never one supplied in the request, before it is acted on.

Web filtering. Company devices use DNS or web filtering that blocks known malicious, phishing, and newly registered domains, on and off the company network.

Network security. Company networks are protected by firewalls that deny inbound traffic by default and are updated and backed up. Servers, operational technology, cameras and other connected devices, and guest Wi-Fi are placed on separate network segments. Wireless networks use WPA2-Enterprise, WPA3, or stronger, and management interfaces of network devices are not reachable from the internet.

9. Logging and Monitoring

Log collection. Security logs are collected in a central location from at least the identity and sign-in system, email, firewalls and VPNs, EDR, servers, cloud administration consoles, and backup systems. System clocks are synchronized to a trusted time source so events can be correlated.

Retention and protection. Logs are kept for at least 12 months, or longer where a law, contract, or legal hold requires. Access to logs is limited, and logs are protected from alteration and deletion.

Alerting. The monitoring service reviews alerts continuously and escalates confirmed threats immediately. At a minimum, alerts are configured for:

  • Repeated failed sign-ins, sign-ins from unusual locations, and bursts of MFA prompts.
  • Creation of new privileged accounts or changes to administrator groups.
  • New email forwarding or inbox rules that move or delete messages.
  • Security tools being disabled, logs being cleared, or backups being deleted.
  • Large or unusual data transfers and mass file changes that may indicate ransomware.

10. Incident Response, Backup and Recovery

Report immediately. Personnel must report a suspected security incident, such as a clicked phishing link, a lost device, a ransom note, or unexpected MFA prompts, to the Information Security Officer immediately. Report even if you are unsure and even if you made a mistake; no one faces retaliation for a good-faith report. Do not turn off, wipe, or try to fix an affected device unless told to, because that can destroy evidence.

Response. Incidents are handled under the company incident response plan, which names the response team and its contacts, how incidents are classified and escalated, and how they are contained, investigated, recovered from, and reviewed afterward. The plan is tested with a tabletop exercise at least once a year. Legal counsel assesses every incident that may involve personal, regulated, or customer information for notification obligations under law and contract, and the Information Security Officer records lessons learned and changes to controls.

Insurer notice. The incident response plan lists the cyber insurer's claim or breach hotline. The Information Security Officer notifies the insurer as the policy requires, and before engaging outside incident response firms, forensic investigators, or legal counsel, because many policies require the use of insurer-approved vendors to preserve coverage.

Backup and recovery. Critical systems and data are backed up automatically, with at least one copy kept offline or immutable so it cannot be changed or deleted by ransomware or a compromised administrator account. Backup systems require MFA and separate credentials. Restores are tested at least quarterly, and recovery time and recovery point objectives for critical systems are documented and approved by the business. Detailed requirements are set in the company data backup and recovery rules.

11. Vendor and Third-Party Risk

Vendors that store or process Confidential or Restricted information, or that can connect to company systems, including IT and security providers, software vendors with remote support access, and cloud services, are critical vendors. The Information Security Officer keeps a list of critical vendors and the information and systems each can reach.

Assessment. Before a contract is signed, and at least once a year after that, each critical vendor is assessed in proportion to its access. The assessment reviews:

  • Independent security reports, such as a SOC 2 Type II report or ISO/IEC 27001 certificate, or a completed security questionnaire.
  • MFA, encryption, and how the vendor controls its own staff access to company information.
  • Incident history, breach notification commitments, and cyber insurance.
  • Where information is stored, which subcontractors are used, and how information is returned or deleted at the end of the contract.

Contract terms. Contracts with critical vendors must require appropriate security controls, confidentiality, prompt notice of security incidents affecting company information, cooperation with investigations, and return or deletion of company information when the contract ends.

Vendor access. Vendor accounts are individual, protected with MFA, limited to the systems needed, and enabled only while work is performed where practical. Vendor remote access sessions are logged, and vendor access is removed when the contract ends.

12. Physical and Environmental Security

  • Server rooms, network closets, and equipment cabinets are locked, with access limited to authorized personnel and reviewed when access lists change.
  • Visitors sign in, are escorted in areas where Confidential information is visible or systems are housed, and do not connect devices to the company network except guest Wi-Fi.
  • Critical equipment is protected by uninterruptible power, appropriate cooling, and fire protection suited to electronic equipment.
  • Screens are locked when unattended, and Confidential and Restricted papers are not left on desks, printers, or in vehicles.
  • Laptops and mobile devices are never left unattended in public places or visible in vehicles, and a lost or stolen device is reported immediately.

13. Security Awareness Training

All personnel complete security awareness training within 30 days of starting, and before receiving access to Restricted information, and again at least once a year. Training covers:

  • This policy and how to report incidents.
  • Recognizing phishing, business email compromise, fake invoices, and phone and text scams, including AI-generated voice and video impersonation.
  • MFA, password managers, and never approving an unexpected sign-in prompt.
  • Handling Confidential and Restricted information and using approved systems only.
  • Safe use of devices at home, while traveling, and on public networks.

Phishing simulations. Simulated phishing tests are sent to all personnel with email at least monthly. People who fall for a simulation receive short follow-up training. Simulations are a learning tool: a failed test alone does not lead to discipline, but repeated disregard of training may be addressed under the enforcement section.

Role-based training. Administrators, developers, finance and payroll staff, and executives receive additional training suited to the risks of their roles. Training completion is recorded and reported to the Information Security Officer.

15. Compliance, Exceptions and Enforcement

Monitoring compliance. The Information Security Officer checks compliance with this policy through automated reports, access reviews, vulnerability scans, training records, and at least one internal review a year. Company systems and accounts may be monitored for security and compliance purposes, in line with applicable law, and personnel should have no expectation of privacy in company systems beyond what the law provides.

Exceptions. Where a requirement cannot be met, a written exception request must be sent to the Information Security Officer, explaining the business need, the risk, the compensating controls, and the date by which the requirement will be met. The Information Security Officer may approve low and moderate risk exceptions; exceptions that create high risk or involve regulated information require approval by the Chief Executive Officer. Exceptions are recorded, limited to no more than 12 months, and reviewed before renewal. No exception may permit something a law or contract prohibits.

Enforcement. Violations of this policy may result in loss of access and disciplinary action, up to and including termination of employment or of a contractor or vendor agreement, consistent with applicable law. Prompt self-reporting of a mistake is taken into account. Deliberately bypassing a security control, or failing to report a known incident, is a serious violation.

Policy review. The Information Security Officer reviews this policy no later than September 27, 2027, and sooner after a significant incident, a major change to systems or the business, or a new legal, contract, or insurance requirement. Changes are approved by the Chief Executive Officer and communicated to personnel.

16. Acknowledgment

I have read and understand the [Company Name] Information Security Policy. I agree to protect company and customer information, to use only approved systems and accounts, to complete required training, and to report suspected security incidents immediately. I understand that company systems may be monitored and that violations may result in disciplinary action.

Name

Job title

Signature

Date

17. Document Control and Revision History

FieldValue
DocumentInformation Security Policy
Organization[Company Name]
Document IDPDC-ISP-SAMPLE
Document version1.0
Effective dateSeptember 27, 2026
Next scheduled reviewSeptember 27, 2027
Policy ownerInformation Security Officer
Approved byChief Executive Officer
Source templatePreferred Data Corporation Information Security Policy template v1.0.0

Revision history. Record every change to this policy below. Increase the document version and obtain approval again each time the policy is revised.

VersionDateDescription of changeApproved by
1.0September 27, 2026Initial adoption, generated from template v1.0.0.Chief Executive Officer
BlankBlankBlankBlank
BlankBlankBlankBlank

18. Template Notice and Legal Disclaimer

This document was generated from a starter template provided by Preferred Data Corporation. It is general information only. It is not legal advice and it is not a substitute for advice from a licensed attorney.

Preferred Data Corporation is not a law firm. It makes no representation that this document is complete, current, or suitable for any particular organization, industry, jurisdiction, or regulatory requirement, and it is not responsible or liable for any use of this template or of any policy created from it. You are solely responsible for how you adapt, adopt, and enforce it.

Laws, regulations, insurance requirements, and contracts that apply to your organization may require different or additional terms. Before you adopt, publish, or rely on this policy, and in every case where you have a legal, regulatory, or contractual obligation, have it reviewed by qualified legal counsel.

How does the Information Security Policy generator work?

6 short phases, about 6 minutes in total. Every question is pre-filled with a best-practice answer and the reason we recommend it.

  1. Your organization

    The basics that shape who the policy covers and which obligations it has to respect.

  2. Security program and risk

    Who runs security day to day and how often risk is assessed and tested.

  3. Access control

    How people sign in, what they can reach, and how quickly access is removed.

  4. Patching, protection and monitoring

    How fast vulnerabilities are fixed and how systems, email and logs are protected.

  5. People and vendors

    Training, phishing tests, vendor checks and signed acknowledgments.

  6. Ownership and review

    Who owns the policy, who approves it, and how it stays current.

  7. Review and download

    Preview your policy, unlock the full document and download it as a PDF with a document ID and review date.

Start the generator

Who should adopt this policy?

  • Owners and executives of small and mid-sized businesses completing a cyber insurance application or renewal.
  • IT managers and outsourced IT providers asked for a written security policy in customer security questionnaires or audits.
  • Manufacturers, contractors and distributors protecting drawings, bids, pricing and plant floor systems.
  • Defense suppliers preparing for CMMC, and healthcare or financial organizations that must keep a written security program.
  • Growing companies that have security tools in place but no document that ties them together.

Which frameworks does this template align with?

The template was written against these public frameworks, laws and standards. Alignment is not certification, and your obligations depend on your industry and location.

Framework or lawWhy it matters for this policy
NIST Cybersecurity Framework (CSF) 2.0(opens in a new tab)The policy is organized around the six CSF 2.0 functions: Govern, Identify, Protect, Detect, Respond and Recover.
CIS Critical Security Controls v8.1(opens in a new tab)Sets the minimum technical controls, and v8.1 aligns its security functions to CSF 2.0, including Govern.
CIS Controls Implementation Group 1 (IG1)(opens in a new tab)The 56 essential cyber hygiene Safeguards this policy treats as the floor for a small or mid-sized organization.
CISA Known Exploited Vulnerabilities Catalog(opens in a new tab)Used by the patch management section to decide which vulnerabilities must be fixed first.
FTC Safeguards Rule: What Your Business Needs to Know(opens in a new tab)Source of the written program, Qualified Individual, testing and 30-day notification requirements applied when GLBA data is selected.
NIST SP 800-171, Protecting Controlled Unclassified Information(opens in a new tab)The CUI security requirements that DFARS 252.204-7012 and CMMC Level 2 build on, applied when CUI is selected.

Information Security Policy questions, answered

What should an information security policy include?

At minimum: governance and roles, risk assessment, asset inventory, data classification, access control and multi-factor authentication, patch and vulnerability management, endpoint and email protection, encryption, logging and monitoring, backup and incident response, vendor risk, physical security, training, and how exceptions and violations are handled. Organizing it around the six NIST CSF 2.0 functions (Govern, Identify, Protect, Detect, Respond, Recover) makes gaps easy to spot. It should name one accountable owner and be approved by an executive.

Is a written information security program legally required?

No single U.S. law requires every business to have one, but many businesses are covered by a rule that does. The FTC Safeguards Rule requires financial institutions under its jurisdiction to keep a written program appropriate to their size and complexity, the HIPAA Security Rule requires covered entities and business associates to assess risks to electronic health information, and Massachusetts 201 CMR 17.00 requires a written program from anyone that owns or licenses personal information about a Massachusetts resident. Defense contractors handling CUI must implement NIST SP 800-171 under DFARS 252.204-7012, and CMMC requirements began phasing into contracts on November 10, 2025.

What is the difference between an information security policy and a WISP?

In practice they are the same document. "Written information security program" is the term used in regulations such as the FTC Safeguards Rule and Massachusetts 201 CMR 17.00, while "information security policy" is the common business term. Either way, the policy sets the rules and responsibilities, and supporting standards and procedures, such as a password standard or an incident response plan, carry the detail.

What are CIS Controls IG1?

Implementation Group 1 (IG1) is the starting tier of the CIS Critical Security Controls: a foundational set of 56 Safeguards that the Center for Internet Security describes as essential cyber hygiene. CIS says a typical IG1 enterprise is small to medium-sized with limited IT and cybersecurity expertise. Asset inventory, secure configuration, access control, patching, malware defense, backups and training are all IG1 Safeguards, which is why this policy uses IG1 as its minimum.

How fast should a small business install security patches?

A common baseline is days for vulnerabilities that are being actively exploited, 14 days for critical, 30 days for high, and 60 to 90 days for everything else. Use the CISA Known Exploited Vulnerabilities catalog to decide what jumps the queue, and remember that PCI DSS v4.0.1 requires critical patches within one month of release on in-scope systems. Speed matters: Verizon found exploitation of vulnerabilities started 20% of breaches in its 2025 report, a 34% increase.

What security controls do cyber insurers require?

Applications commonly ask about multi-factor authentication for email, remote access and administrator accounts, endpoint detection and response, backups kept offline or immutable, patching timelines, security awareness training with phishing simulation, and a written incident response plan. MFA is usually the first question because it works: Microsoft Research found it reduces the risk of account compromise by 99.22%. Answer every question accurately, because an inaccurate application can put a claim at risk.

How often should an information security policy be reviewed?

Review it at least once a year and after any major incident, significant system change, acquisition, or new legal or contract requirement. The FTC Safeguards Rule, for example, requires the Qualified Individual to report in writing to the board or governing body regularly and at least annually. Record every revision and have it re-approved by an executive.

Related policy templates

Services that put this policy into practice

Want help rolling out your Information Security Policy?

A policy works when the tools, training and controls behind it do. Preferred Data Corporation helps North Carolina businesses put policies like this one into practice, from High Point since 1987.