# Information Security Policy

> **Template — adapt before use.** Replace every `[bracketed]` placeholder, delete guidance notes in _italics_, and have an accountable owner approve it. Provided by SentinelPanda as a starting point; it is not legal or compliance advice.

| | |
|---|---|
| **Owner** | [Name / Role — e.g. CISO] |
| **Approved by** | [Name / Title] |
| **Approved date** | [YYYY-MM-DD] |
| **Review cadence** | Annual (or after any material change) |
| **Version** | 1.0 |

## 1. Purpose
This policy defines how [Company Name] protects the confidentiality, integrity, and availability of its information and information systems. It is the umbrella policy under which all other security policies and procedures sit.

## 2. Scope
This policy applies to all employees, contractors, and third parties who access [Company Name] information, systems, or facilities, and to all information assets the company owns or processes — regardless of format or location.

## 3. Roles and responsibilities
- **Management** is accountable for resourcing the security program and approving this policy.
- **The security function** ([role]) maintains the program, policies, and risk register.
- **Asset and system owners** apply the controls relevant to the assets they own.
- **All personnel** are responsible for following this policy and reporting suspected incidents.

## 4. Policy statements
- **Risk management.** Security risks are identified, assessed, and treated on a documented, recurring basis (see _Risk Management Policy_).
- **Access control.** Access to systems and data is granted on least-privilege and need-to-know, and reviewed periodically (see _Access Control Policy_).
- **Data protection.** Information is classified and handled according to its sensitivity (see _Data Classification Policy_); sensitive data is encrypted in transit and at rest.
- **Operations.** Changes are managed, systems are patched on a defined schedule, and security events are logged and reviewed.
- **Incident response.** Suspected incidents are reported and handled per the _Incident Response Plan_.
- **Resilience.** Backups and continuity arrangements are maintained and tested (see _Business Continuity Policy_).
- **Third parties.** Vendors that handle company or customer data are assessed and bound by contract (see _Vendor Management Policy_).
- **Awareness.** Personnel receive security training at onboarding and at least annually.

## 5. Compliance and enforcement
Violations of this policy may result in disciplinary action up to and including termination, and may be reported to authorities where required by law. Exceptions must be requested in writing and approved by the policy owner with a documented compensating control and expiry date.

## 6. Related documents
Access Control Policy · Acceptable Use Policy · Incident Response Plan · Risk Management Policy · Data Classification Policy · Vendor Management Policy · Business Continuity Policy.

## Revision history
| Version | Date | Author | Change |
|---|---|---|---|
| 1.0 | [YYYY-MM-DD] | [Name] | Initial issue |
