Best Practice Information Security Guideline
Information Security Policy: The Strategic Foundation of Your ISMS
Section titled “Information Security Policy: The Strategic Foundation of Your ISMS”What is an Information Security Policy?
Section titled “What is an Information Security Policy?”The Information Security Policy is the central strategic foundation document of every Information Security Management System (ISMS). It defines at the highest level the objectives, responsibilities, and framework conditions for information security in your organization.
The policy is adopted and signed by executive management and thus documents the leadership’s commitment to information security. It is binding for all employees and forms the basis for all further security measures.
Typical Characteristics
Section titled “Typical Characteristics”- Scope: 3 to 8 pages
- Level: Strategic (no technical details)
- Scope: Entire organization
- Updates: Every 1-5 years
- Approval: Executive management
Distinction from Other Security Documents
Section titled “Distinction from Other Security Documents”The Information Security Policy is often confused with other security documents. Here are the key differences:
Information Security Policy vs. Information Security Concept
Section titled “Information Security Policy vs. Information Security Concept”The Information Security Concept (IS Concept) is the central technical document of the ISMS and describes:
- Asset protection requirements assessment
- Risk analysis and risk assessment
- Concrete security measures (technical and organizational)
- Implementation planning and prioritization
The Policy, however, defines the strategic framework under which the IS Concept is created. It answers the “Why” and “What”, while the IS Concept answers the “How”.
Rule of thumb: You can show the Policy to any employee - the IS Concept only to technical staff.
Distinction: Information Security Policy vs. Security Guideline
Section titled “Distinction: Information Security Policy vs. Security Guideline”Overview: Two Levels of Control
Section titled “Overview: Two Levels of Control”The Information Security Policy (IS Policy) and Security Guidelines (e.g., Password Guideline) are different document types in the ISMS that complement each other but have clearly distinguishable functions:
- The IS Policy defines the strategic “WHAT” and “WHY”
- The Security Guideline defines the concrete “HOW”
Detailed Comparison
Section titled “Detailed Comparison”| Characteristic | Information Security Policy | Security Guideline (e.g., Password Guideline) |
|---|---|---|
| Level | Strategic | Tactical |
| Purpose | Commitment to IS, objectives and responsibilities | Concrete behavioral rules for a specific topic |
| Validity | Entire organization | Topic-specific (e.g., all authentication processes) |
| Target Audience | All employees and executive management | All password users (can be more specific) |
| Approval | Executive management | Information Security Officer (ISO), IT Management |
| Level of Detail | Principles and framework | Concrete rules and requirements |
| Scope | 3-8 pages | 2-5 pages |
| Updates | Every 1-5 years | Every 1-3 years, earlier for technical changes |
| Binding Nature | Overarching commitment document | Directly enforceable instructions |
| Key Question | “What do we want to achieve?” | “How should employees behave concretely?” |
Why is an Information Security Policy Important?
Section titled “Why is an Information Security Policy Important?”1. NIS2 Compliance and Executive Liability
Section titled “1. NIS2 Compliance and Executive Liability”The NIS2 Directive brings a fundamental change: The personal liability of executive management for cybersecurity.
What does this mean in practice?
- Executive management is personally responsible for appropriate cybersecurity measures
- Fines for violations: Up to 10 million euros or 2% of global annual revenue
- Personal liability of executives possible
- Mandatory participation in cybersecurity training
An Information Security Policy is therefore essential to:
- Clearly define responsibilities (who is responsible for what?)
- Document management commitment (evidence for authorities)
- Create legal certainty (in case of audits or incidents)
- Demonstrate compliance (to BSI, regulatory authorities, customers)
Important: Without a clear policy, executives cannot prove in the event of damage that they have fulfilled their duty of care.
2. Basis for ISO 27001 and IT-Grundschutz Certification
Section titled “2. Basis for ISO 27001 and IT-Grundschutz Certification”Both ISO/IEC 27001 and the BSI IT-Grundschutz explicitly require an Information Security Policy. Without this document, no certification is possible.
3. Trust from Customers and Business Partners
Section titled “3. Trust from Customers and Business Partners”In tenders, an Information Security Policy is increasingly required. It signals:
- Professional security management
- Clear responsibilities
- Management commitment
4. Internal Clarity and Commitment
Section titled “4. Internal Clarity and Commitment”The policy creates clarity for all employees about:
- Security objectives of the organization
- Their role and responsibility
- Fundamental security principles
- Consequences of violations
What Must Be Included in an Information Security Policy?
Section titled “What Must Be Included in an Information Security Policy?”A complete IS Policy contains the following topics:
| Section | Must / Should | Content |
|---|---|---|
| 1. Introduction & Scope | Must | Purpose of the document, who is affected (employees, locations, systems) |
| 2. Importance of Information Security | Must | Significance for the organization, IT dependency, threat scenarios |
| 3. Security Objectives | Must | Confidentiality, Integrity, Availability + organization-specific objectives |
| 4. Responsibilities | Must | Executive management, ISO, IT management, employees - who does what? |
| 5. Compliance with Laws | Must | GDPR, national data protection laws, commercial codes, NIS2, industry-specific requirements |
| 6. ISMS Organization | Must | Roles (ISO, IT management, ISMS team), tasks, reporting lines |
| 7. Security Strategy | Should | ISMS approach (ISO 27001, IT-Grundschutz), risk analysis, PDCA cycle |
| 8. Principles | Should | Minimum principle (need-to-know), maximum principle (appropriate protection) |
| 9. Consequences of Violations | Should | Employment law and possibly criminal law consequences |
| 10. Continuous Improvement | Must | Review intervals, responsibilities for updates |
| 11. Entry into Force | Must | Date, signature of executive management |
Particularly Important for NIS2-Affected Organizations
Section titled “Particularly Important for NIS2-Affected Organizations”- Clear designation of the Information Security Officer (ISO)
- Resource commitment from executive management (personnel, budget, time)
- Annual review by executive management (management review)
- Commitment to training (for executive management and employees)
Best Practice Examples
Section titled “Best Practice Examples”The German Federal Office for Information Security (BSI) and the State of North Rhine-Westphalia provide practical examples:
BSI Best Practice: RECPLAST GmbH
Section titled “BSI Best Practice: RECPLAST GmbH”An excellent example for medium-sized companies and industrial operations.
📄 Download BSI RECPLAST Sample Policy
Ministry of Education North Rhine-Westphalia
Section titled “Ministry of Education North Rhine-Westphalia”An example from public administration with focus on decentralized structures.
📄 Download NRW Information Security Policy
Tips for Your Policy
Section titled “Tips for Your Policy”Avoid these common mistakes:
-
Too generic → Incorporate organization-specific elements (industry, concrete business processes, specific threats)
-
Too technical → Stay at the strategic level, understandable for all employees - not just IT experts
-
No management signature → Without executive management signature, the policy lacks binding force
-
Unrealistic objectives → Set measurable, achievable goals instead of “100% security” or “zero downtime”
-
“Paper tiger” document → Live the policy actively: communicate, train, sanction violations
-
Never updated → Establish fixed review intervals (at least annually) and maintain them
-
Unclear responsibilities → Name specifically: Who is the ISO? Who is responsible for which areas?
Next Steps
Section titled “Next Steps”1. Analysis
Section titled “1. Analysis”Understand your organization: business processes, IT landscape, legal requirements (check NIS2 status!)
2. Draft
Section titled “2. Draft”Use the BSI or NRW template as a starting point and adapt it to your organization.
3. Coordination
Section titled “3. Coordination”Get feedback from IT management, data protection officer, legal department, and works council.
4. Adoption
Section titled “4. Adoption”Have the policy signed by executive management and set an effective date.
5. Communication
Section titled “5. Communication”Make the policy known to all employees (intranet, training, onboarding).
6. Live It
Section titled “6. Live It”The policy is not a “paper tiger” - live the content and review it regularly (at least annually).