DOC-001 ← Document Portal

Information Security Policy

Main document of the Information Security Management System (ISMS)
Document Number
DOC-001
Version
▸ e.g. 1.0
Status
DRAFT
Issue Date
▸ DD/MM/YYYY
Next Review
▸ DD/MM/YYYY
Document Owner
▸ [First Last Name / role – e.g. CISO]
Approved by
▸ [Board / CEO / appropriate governing body]
Legal Basis
Art. 21 NIS2 Directive; GDPR Art. 32; ISO/IEC 27001:2022

Colour Legend

Yellow – organisation enters its own value (no constraints)
Orange – value with constraint (min/max requirement)
Blue – reference to another document
Red – critical field required by NIS2

1. Purpose and Scope

1.1 Purpose

This Information Security Policy (hereinafter "the Policy") establishes the framework for protecting information processed by the organisation, setting out the fundamental principles, roles and responsibilities in the field of information security. The Policy forms the foundation of the Information Security Management System (ISMS) and responds to the requirements of the NIS2 Directive and ISO/IEC 27001:2022.

The objectives of this Policy are to:

  • Ensure the confidentiality, integrity and availability of information,
  • Protect information systems against cyber threats,
  • Meet NIS2 regulatory requirements,
  • Minimise operational and reputational risks.

1.2 Scope

⚠ Critical field – required by NIS2

This Policy applies to:

  • Entity: ▸ [full legal name of organisation, Organisation ID / Registration Number, registered address]
  • Sector (NIS2 Annex I/II): ▸ [e.g. energy / transport / banking / healthcare / digital infrastructure / other]
  • Category: ▸ [essential entity / important entity – per NIS2 Annex I/II]
  • Scope: ▸ [all locations / branches / IT/OT systems of the organisation]

The Policy applies to all employees, contractors, suppliers and any other persons who have access to the organisation's information or systems.

1.3 Key / Important Services

⚠ Critical field – list of key/important services

The organisation provides the following key/important services under NIS2:

#Service NameDescriptionDependent Systems
1▸ [e.g. Distribution network management system]▸ service description▸ DOC-020
2▸ [service name 2]
3▸ [service name 3]

2. Definitions

TermDefinition
Information securityPreservation of confidentiality, integrity and availability of information (CIA triad)
IncidentAn event having an actual adverse effect on the security of network and information systems
Significant incidentAn incident causing major disruption or likely to cause major disruption to key/important services (threshold defined in DOC-005)
CSIRTComputer Security Incident Response Team (National CSIRT / Sector CSIRT)
ISMSInformation Security Management System – a set of policies, procedures, processes and systems for managing information security risk
RiskThe probability of an event occurring and its impact on the organisation's objectives
Information assetAny information or information system that has value to the organisation
Essential entityEntity meeting the criteria of NIS2 Annex I (large enterprise in high-criticality sectors)
Important entityEntity meeting the criteria of NIS2 Annex I/II (medium enterprise in high-criticality or other critical sectors)
MFAMulti-Factor Authentication
RTORecovery Time Objective – maximum acceptable time to restore a service
RPORecovery Point Objective – maximum acceptable data loss point (looking backwards)

3. Information Security Principles

3.1 Least-privilege principle

Every user, system and process receives only the minimum permissions necessary to perform assigned tasks. Detailed rules in DOC-008.

3.2 Need-to-know principle

Access to information is granted only to persons for whom that information is essential to carry out their duties.

3.3 Defence in depth

The organisation employs layered security measures so that a breach of one layer does not immediately compromise the whole.

3.4 Accountability

Every action in information systems must be attributable to a specific user and recorded in logs. Logs are retained for a minimum of ▸ [12 months]min. 12 months – NIS2.

3.5 Risk-based approach

All information security decisions are made on the basis of a risk assessment conducted in accordance with DOC-002.

3.6 Continual improvement

The ISMS is subject to regular review and improvement based on audit results, lessons learned from incidents and the evolving threat landscape.

3.7 Security by design

Security is considered from the outset when designing systems, processes and services, not added as an afterthought.

4. Roles and Responsibilities

ℹ️
A detailed RACI matrix for all security roles is contained in DOC-004. The key roles required by NIS2 are summarised below.

4.1 Board / Senior Management

⚠ Critical – Art. 21(1) NIS2: management body accountability

The management body is responsible for:

  • Approving this Policy and all related ISMS documents,
  • Providing adequate resources (budget, personnel) for implementing the ISMS,
  • Overseeing the implementation of cybersecurity risk management measures,
  • Attending cybersecurity training min. once/year – NIS2,
  • Personal accountability for non-compliance with NIS2 requirements.

Composition of the responsible management body: ▸ [CEO / Board members – name specific individuals]

4.2 Person responsible for cybersecurity (CISO)

⚠ Critical – NIS2 requirement: designation of a responsible person

Name: ▸ [First Last Name]

Title: ▸ [e.g. Chief Information Security Officer / Cybersecurity Manager]

Contact: ▸ [business e-mail, telephone]

Responsibilities: ISMS coordination, risk management, incident oversight, reporting to the Board and CSIRT, maintaining documentation.

4.3 Information system owner

Each information system has a designated business owner responsible for information classification, risk acceptance decisions and recovery priorities. List of system owners in DOC-020.

4.4 System administrator

Responsible for the technical implementation of security measures, patch management, configuration management and backup creation.

4.5 End users

Every employee and contractor with access to the organisation's systems is required to:

  • Comply with this Policy and related procedures,
  • Immediately report suspicious events in accordance with DOC-005,
  • Attend cybersecurity training (see DOC-017).

5. Information Security Management System Areas

The organisation implements an ISMS covering the following areas, each governed by a separate document:

AreaNIS2 RequirementDocumentStatus
Risk managementArt. 21(2)(a) NIS2DOC-002READY
Incident managementArt. 21(2)(b) NIS2DOC-005, 006, 007DRAFT
Business continuity / BCPArt. 21(2)(c) NIS2DOC-011, 012DRAFT
Supply chain securityArt. 21(2)(d) NIS2DOC-015DRAFT
Acquisition, development and maintenance securityArt. 21(2)(e) NIS2DOC-013DRAFT
Effectiveness assessmentArt. 21(2)(f) NIS2DOC-021DRAFT
Cyber hygiene and trainingArt. 21(2)(g) NIS2DOC-017DRAFT
Cryptography and encryptionArt. 21(2)(h) NIS2DOC-009DRAFT
HR securityArt. 21(2)(i) NIS2DOC-016DRAFT
Access control and MFAArt. 21(2)(j) NIS2DOC-008DRAFT

6. Compliance and Enforcement

6.1 Obligation to comply

Violation of this Policy or related ISMS documents by employees may result in disciplinary action, up to and including termination of employment. Violations by third parties may result in termination of contract. Details in DOC-016.

6.2 Administrative fines (NIS2)

⚠️
Sanctions for essential entities: administrative fines up to 10,000,000 EUR or 2% of annual turnover (whichever is higher).
Sanctions for important entities: up to 7,000,000 EUR or 1.4% of annual turnover.
Personal liability of management for ensuring compliance.

6.3 Exceptions and deviations

Any deviations from Policy requirements must be approved in writing by ▸ [CISO / Board], documented and time-limited. The exceptions register is maintained by ▸ [CISO / relevant department].

7. Communication, Implementation and Training

This Policy is:

  • Made available to all employees via ▸ [intranet / HR system / internal portal],
  • Discussed during induction training for new employees,
  • Confirmed by signature or electronic acknowledgement by each employee min. once/year,
  • Incorporated into contracts with suppliers and partners having access to the organisation's systems.

Details of the training programme in DOC-017.

8. Document Management and Reviews

8.1 Review cycle

This Policy is subject to review:

  • Regularly, at least once every ▸ [12 months]max. 12 months – NIS2,
  • After any significant security incident,
  • Following significant organisational or technological changes,
  • Following changes in legislation.

8.2 Change History

VersionDateAuthorDescriptionApproved by
▸ 1.0 ▸ DD/MM/YYYY ▸ First Last Name ▸ Initial release ▸ Board/CEO

8.3 Related Documents

DocumentRelationship
DOC-002 Risk Management ProcedureElaboration of section 3.5 (risk principle)
DOC-003 Risk RegisterOperational register of risks identified per DOC-002
DOC-004 Roles & RACIDetailed responsibility matrix for section 4
DOC-005 Incident PolicyImplementation of the incident management area
DOC-008 Access ControlImplementation of principle 3.1 (least privilege)

9. Approval

📝
The signatures below confirm that this Policy has been read and approved. In accordance with Art. 21(1) NIS2, the management body is responsible for approving risk management measures.
RoleNameDateSignature
Document Owner (CISO) ▸ [First Last Name] ▸ DD/MM/YYYY ____________________
Approving authority (Board/CEO) ▸ [First Last Name] ▸ DD/MM/YYYY ____________________
DOC-001 Information Security Policy | v1.0 | NIS2/ISMS