betterjobs

Free policy template · Word

Information Security Policy

An information security policy is the management-approved framework for protecting the confidentiality, integrity and availability of company information. It covers roles, data classification, access control, physical security, backups, vendor security and incident response, including reporting cyber incidents to authorities where required.

  • Editable Word (.docx)
  • Made for India
  • 10 fill-in fields highlighted
  • Free, no sign-up

Preview of the policy

[Highlighted] = fill in
[Company Logo][Company Name]

INFORMATION SECURITY POLICY

Policy No.:
[Reference Number]
Version:
[Version Number]
Effective Date:
[Date]
Policy Owner:
Information Security Officer

1. Purpose

[Company Name] is committed to protecting the confidentiality, integrity and availability of information belonging to the company, its customers and employees. This policy sets the framework of controls and responsibilities to achieve this.

2. Scope

It covers all information in any form (digital, paper, verbal), all systems that store or process it, and all employees, contractors and vendors with access.

3. Definitions

  • Information asset: any data, system, device or document of value to the company.
  • Security incident: an event that compromises, or may compromise, information or systems.
  • Least privilege: giving users only the access needed for their role.

4. Policy

ClassificationExamplesHandling
PublicWebsite content, brochuresNo restriction
InternalPolicies, org chartsEmployees only
ConfidentialContracts, pricing, employee recordsNeed-to-know, encrypted in transit
RestrictedCustomer personal data, source code, financials before releaseNamed access, encrypted at rest and in transit, logged
  1. Governance: the Information Security Officer leads the programme and reports to [Authorised Signatory]; a security committee meets every [Number] months.
  2. Asset management: all information assets are recorded with an owner and classification.
  3. Access control: access is granted on least privilege, approved by the asset owner, reviewed every [Number] months and removed within [Number] hours of exit.
  4. Physical security: offices and server rooms have controlled entry and visitor logs.
  5. Operations: systems are patched within [Number] days of critical updates; antivirus and logging are enabled.
  6. Backup: critical data is backed up [daily] and restoration tested every [Number] months.
  7. Vendors: suppliers handling confidential data sign confidentiality and security terms and are assessed before onboarding.
  8. Awareness: all staff complete security training on joining and annually.

5. Procedure – Incident Response

  1. Anyone noticing a suspected incident reports it immediately to [Security Email / Phone].
  2. The security team assesses severity and contains the incident.
  3. Where reporting to CERT-In, the Data Protection Board, customers or other authorities is required, the Information Security Officer coordinates it within the applicable timelines with legal advice.
  4. A post-incident review records root cause and corrective actions.

6. Responsibilities

  • Management: approve policy and resources.
  • Information Security Officer: run the programme and incident response.
  • Asset owners: classify and approve access.
  • All users: follow policies, protect credentials and report incidents.

7. Non-compliance

Breaches of this policy may lead to disciplinary action, termination of vendor contracts and, where applicable, legal action. Exceptions require written approval from the Information Security Officer with a documented risk acceptance.

8. Review & Approval

This policy is reviewed annually and after any major incident or change in law.

Prepared by
[Information Security Officer]
Approved by
[Authorised Signatory]
[Designation]
Date: [Date]

What this template includes

  • Security governance — named Information Security Officer
  • Data classification — Public, Internal, Confidential, Restricted
  • Access control — least privilege, periodic reviews
  • Backups and business continuity
  • Vendor and third-party security
  • Incident response — detect, contain, report, learn

When to use it

  • Starting an ISO 27001 or SOC 2 programme
  • Enterprise clients send security questionnaires
  • No one is clearly accountable for security decisions
  • Setting up an incident response process

How to customise this template

  1. 1Name the Information Security Officer and committee
  2. 2Edit the classification table for your data types
  3. 3Set backup frequency and recovery targets
  4. 4Insert vendor assessment requirements
  5. 5Confirm current incident-reporting obligations with your legal adviser

HR tips

  • Classify data first — controls follow classification
  • Review user access every quarter, especially for admins
  • Test backups by restoring them, not just by running them
  • Run phishing awareness training at least twice a year

Cyber incident reporting and data protection obligations arise under the Information Technology Act, 2000, CERT-In directions and the Digital Personal Data Protection Act, 2023. Review timelines and duties with legal and security advisers.

For HR & hiring managers

Hire top talent from BetterJobs

Experienced and fresher candidates across India — blue, grey and white collar. Post a job in 5 minutes and start receiving applications.

  • Post in 5 minutesDescribe the role in one line — we write the job description.
  • Verified applicantsEvery applicant has a verified mobile number.
  • Resume databaseSearch experienced candidates by skill, city and experience.

Frequently asked questions

What is the CIA triad?+

Confidentiality (only authorised people access information), Integrity (information is accurate and unaltered) and Availability (information is accessible when needed) — the three goals of information security.

Do companies have to report cyber incidents in India?+

CERT-In directions require specified types of cyber incidents to be reported within set timelines. Check the current directions with your legal or security adviser and build them into your incident procedure.

Is this policy enough for ISO 27001?+

No. ISO 27001 requires a full management system — risk assessment, statement of applicability, procedures and audits. This policy is the top-level document that the system builds on.

All 50 hr policies →