Skip to content

Best Practice Information Security Guideline

Information Security Policy: The Strategic Foundation of Your ISMS

Section titled “Information Security Policy: The Strategic Foundation of Your ISMS”

The Information Security Policy is the central strategic foundation document of every Information Security Management System (ISMS). It defines at the highest level the objectives, responsibilities, and framework conditions for information security in your organization.

The policy is adopted and signed by executive management and thus documents the leadership’s commitment to information security. It is binding for all employees and forms the basis for all further security measures.

  • Scope: 3 to 8 pages
  • Level: Strategic (no technical details)
  • Scope: Entire organization
  • Updates: Every 1-5 years
  • Approval: Executive management

The Information Security Policy is often confused with other security documents. Here are the key differences:

Information Security Policy vs. Information Security Concept

Section titled “Information Security Policy vs. Information Security Concept”

The Information Security Concept (IS Concept) is the central technical document of the ISMS and describes:

  • Asset protection requirements assessment
  • Risk analysis and risk assessment
  • Concrete security measures (technical and organizational)
  • Implementation planning and prioritization

The Policy, however, defines the strategic framework under which the IS Concept is created. It answers the “Why” and “What”, while the IS Concept answers the “How”.

Rule of thumb: You can show the Policy to any employee - the IS Concept only to technical staff.


Distinction: Information Security Policy vs. Security Guideline

Section titled “Distinction: Information Security Policy vs. Security Guideline”

The Information Security Policy (IS Policy) and Security Guidelines (e.g., Password Guideline) are different document types in the ISMS that complement each other but have clearly distinguishable functions:

  • The IS Policy defines the strategic “WHAT” and “WHY”
  • The Security Guideline defines the concrete “HOW”

CharacteristicInformation Security PolicySecurity Guideline (e.g., Password Guideline)
LevelStrategicTactical
PurposeCommitment to IS, objectives and responsibilitiesConcrete behavioral rules for a specific topic
ValidityEntire organizationTopic-specific (e.g., all authentication processes)
Target AudienceAll employees and executive managementAll password users (can be more specific)
ApprovalExecutive managementInformation Security Officer (ISO), IT Management
Level of DetailPrinciples and frameworkConcrete rules and requirements
Scope3-8 pages2-5 pages
UpdatesEvery 1-5 yearsEvery 1-3 years, earlier for technical changes
Binding NatureOverarching commitment documentDirectly enforceable instructions
Key Question“What do we want to achieve?”“How should employees behave concretely?”

Why is an Information Security Policy Important?

Section titled “Why is an Information Security Policy Important?”

1. NIS2 Compliance and Executive Liability

Section titled “1. NIS2 Compliance and Executive Liability”

The NIS2 Directive brings a fundamental change: The personal liability of executive management for cybersecurity.

What does this mean in practice?

  • Executive management is personally responsible for appropriate cybersecurity measures
  • Fines for violations: Up to 10 million euros or 2% of global annual revenue
  • Personal liability of executives possible
  • Mandatory participation in cybersecurity training

An Information Security Policy is therefore essential to:

  1. Clearly define responsibilities (who is responsible for what?)
  2. Document management commitment (evidence for authorities)
  3. Create legal certainty (in case of audits or incidents)
  4. Demonstrate compliance (to BSI, regulatory authorities, customers)

Important: Without a clear policy, executives cannot prove in the event of damage that they have fulfilled their duty of care.

2. Basis for ISO 27001 and IT-Grundschutz Certification

Section titled “2. Basis for ISO 27001 and IT-Grundschutz Certification”

Both ISO/IEC 27001 and the BSI IT-Grundschutz explicitly require an Information Security Policy. Without this document, no certification is possible.

3. Trust from Customers and Business Partners

Section titled “3. Trust from Customers and Business Partners”

In tenders, an Information Security Policy is increasingly required. It signals:

  • Professional security management
  • Clear responsibilities
  • Management commitment

The policy creates clarity for all employees about:

  • Security objectives of the organization
  • Their role and responsibility
  • Fundamental security principles
  • Consequences of violations

What Must Be Included in an Information Security Policy?

Section titled “What Must Be Included in an Information Security Policy?”

A complete IS Policy contains the following topics:

SectionMust / ShouldContent
1. Introduction & ScopeMustPurpose of the document, who is affected (employees, locations, systems)
2. Importance of Information SecurityMustSignificance for the organization, IT dependency, threat scenarios
3. Security ObjectivesMustConfidentiality, Integrity, Availability + organization-specific objectives
4. ResponsibilitiesMustExecutive management, ISO, IT management, employees - who does what?
5. Compliance with LawsMustGDPR, national data protection laws, commercial codes, NIS2, industry-specific requirements
6. ISMS OrganizationMustRoles (ISO, IT management, ISMS team), tasks, reporting lines
7. Security StrategyShouldISMS approach (ISO 27001, IT-Grundschutz), risk analysis, PDCA cycle
8. PrinciplesShouldMinimum principle (need-to-know), maximum principle (appropriate protection)
9. Consequences of ViolationsShouldEmployment law and possibly criminal law consequences
10. Continuous ImprovementMustReview intervals, responsibilities for updates
11. Entry into ForceMustDate, signature of executive management

Particularly Important for NIS2-Affected Organizations

Section titled “Particularly Important for NIS2-Affected Organizations”
  • Clear designation of the Information Security Officer (ISO)
  • Resource commitment from executive management (personnel, budget, time)
  • Annual review by executive management (management review)
  • Commitment to training (for executive management and employees)

The German Federal Office for Information Security (BSI) and the State of North Rhine-Westphalia provide practical examples:

An excellent example for medium-sized companies and industrial operations.

📄 Download BSI RECPLAST Sample Policy

Ministry of Education North Rhine-Westphalia

Section titled “Ministry of Education North Rhine-Westphalia”

An example from public administration with focus on decentralized structures.

📄 Download NRW Information Security Policy


Avoid these common mistakes:

  • Too generic → Incorporate organization-specific elements (industry, concrete business processes, specific threats)

  • Too technical → Stay at the strategic level, understandable for all employees - not just IT experts

  • No management signature → Without executive management signature, the policy lacks binding force

  • Unrealistic objectives → Set measurable, achievable goals instead of “100% security” or “zero downtime”

  • “Paper tiger” document → Live the policy actively: communicate, train, sanction violations

  • Never updated → Establish fixed review intervals (at least annually) and maintain them

  • Unclear responsibilities → Name specifically: Who is the ISO? Who is responsible for which areas?


Understand your organization: business processes, IT landscape, legal requirements (check NIS2 status!)

Use the BSI or NRW template as a starting point and adapt it to your organization.

Get feedback from IT management, data protection officer, legal department, and works council.

Have the policy signed by executive management and set an effective date.

Make the policy known to all employees (intranet, training, onboarding).

The policy is not a “paper tiger” - live the content and review it regularly (at least annually).