Information Security Policy
Colour Legend
1. Purpose and Scope
1.1 Purpose
This Information Security Policy (hereinafter "the Policy") establishes the framework for protecting information processed by the organisation, setting out the fundamental principles, roles and responsibilities in the field of information security. The Policy forms the foundation of the Information Security Management System (ISMS) and responds to the requirements of the NIS2 Directive and ISO/IEC 27001:2022.
The objectives of this Policy are to:
- Ensure the confidentiality, integrity and availability of information,
- Protect information systems against cyber threats,
- Meet NIS2 regulatory requirements,
- Minimise operational and reputational risks.
1.2 Scope
This Policy applies to:
- Entity: ▸ [full legal name of organisation, Organisation ID / Registration Number, registered address]
- Sector (NIS2 Annex I/II): ▸ [e.g. energy / transport / banking / healthcare / digital infrastructure / other]
- Category: ▸ [essential entity / important entity – per NIS2 Annex I/II]
- Scope: ▸ [all locations / branches / IT/OT systems of the organisation]
The Policy applies to all employees, contractors, suppliers and any other persons who have access to the organisation's information or systems.
1.3 Key / Important Services
The organisation provides the following key/important services under NIS2:
| # | Service Name | Description | Dependent Systems |
|---|---|---|---|
| 1 | ▸ [e.g. Distribution network management system] | ▸ service description | ▸ DOC-020 |
| 2 | ▸ [service name 2] | ▸ | ▸ |
| 3 | ▸ [service name 3] | ▸ | ▸ |
2. Definitions
| Term | Definition |
|---|---|
| Information security | Preservation of confidentiality, integrity and availability of information (CIA triad) |
| Incident | An event having an actual adverse effect on the security of network and information systems |
| Significant incident | An incident causing major disruption or likely to cause major disruption to key/important services (threshold defined in DOC-005) |
| CSIRT | Computer Security Incident Response Team (National CSIRT / Sector CSIRT) |
| ISMS | Information Security Management System – a set of policies, procedures, processes and systems for managing information security risk |
| Risk | The probability of an event occurring and its impact on the organisation's objectives |
| Information asset | Any information or information system that has value to the organisation |
| Essential entity | Entity meeting the criteria of NIS2 Annex I (large enterprise in high-criticality sectors) |
| Important entity | Entity meeting the criteria of NIS2 Annex I/II (medium enterprise in high-criticality or other critical sectors) |
| MFA | Multi-Factor Authentication |
| RTO | Recovery Time Objective – maximum acceptable time to restore a service |
| RPO | Recovery Point Objective – maximum acceptable data loss point (looking backwards) |
3. Information Security Principles
3.1 Least-privilege principle
Every user, system and process receives only the minimum permissions necessary to perform assigned tasks. Detailed rules in DOC-008.
3.2 Need-to-know principle
Access to information is granted only to persons for whom that information is essential to carry out their duties.
3.3 Defence in depth
The organisation employs layered security measures so that a breach of one layer does not immediately compromise the whole.
3.4 Accountability
Every action in information systems must be attributable to a specific user and recorded in logs. Logs are retained for a minimum of ▸ [12 months]min. 12 months – NIS2.
3.5 Risk-based approach
All information security decisions are made on the basis of a risk assessment conducted in accordance with DOC-002.
3.6 Continual improvement
The ISMS is subject to regular review and improvement based on audit results, lessons learned from incidents and the evolving threat landscape.
3.7 Security by design
Security is considered from the outset when designing systems, processes and services, not added as an afterthought.
4. Roles and Responsibilities
4.1 Board / Senior Management
The management body is responsible for:
- Approving this Policy and all related ISMS documents,
- Providing adequate resources (budget, personnel) for implementing the ISMS,
- Overseeing the implementation of cybersecurity risk management measures,
- Attending cybersecurity training min. once/year – NIS2,
- Personal accountability for non-compliance with NIS2 requirements.
Composition of the responsible management body: ▸ [CEO / Board members – name specific individuals]
4.2 Person responsible for cybersecurity (CISO)
Name: ▸ [First Last Name]
Title: ▸ [e.g. Chief Information Security Officer / Cybersecurity Manager]
Contact: ▸ [business e-mail, telephone]
Responsibilities: ISMS coordination, risk management, incident oversight, reporting to the Board and CSIRT, maintaining documentation.
4.3 Information system owner
Each information system has a designated business owner responsible for information classification, risk acceptance decisions and recovery priorities. List of system owners in DOC-020.
4.4 System administrator
Responsible for the technical implementation of security measures, patch management, configuration management and backup creation.
4.5 End users
Every employee and contractor with access to the organisation's systems is required to:
5. Information Security Management System Areas
The organisation implements an ISMS covering the following areas, each governed by a separate document:
| Area | NIS2 Requirement | Document | Status |
|---|---|---|---|
| Risk management | Art. 21(2)(a) NIS2 | DOC-002 | READY |
| Incident management | Art. 21(2)(b) NIS2 | DOC-005, 006, 007 | DRAFT |
| Business continuity / BCP | Art. 21(2)(c) NIS2 | DOC-011, 012 | DRAFT |
| Supply chain security | Art. 21(2)(d) NIS2 | DOC-015 | DRAFT |
| Acquisition, development and maintenance security | Art. 21(2)(e) NIS2 | DOC-013 | DRAFT |
| Effectiveness assessment | Art. 21(2)(f) NIS2 | DOC-021 | DRAFT |
| Cyber hygiene and training | Art. 21(2)(g) NIS2 | DOC-017 | DRAFT |
| Cryptography and encryption | Art. 21(2)(h) NIS2 | DOC-009 | DRAFT |
| HR security | Art. 21(2)(i) NIS2 | DOC-016 | DRAFT |
| Access control and MFA | Art. 21(2)(j) NIS2 | DOC-008 | DRAFT |
6. Compliance and Enforcement
6.1 Obligation to comply
Violation of this Policy or related ISMS documents by employees may result in disciplinary action, up to and including termination of employment. Violations by third parties may result in termination of contract. Details in DOC-016.
6.2 Administrative fines (NIS2)
Sanctions for important entities: up to 7,000,000 EUR or 1.4% of annual turnover.
Personal liability of management for ensuring compliance.
6.3 Exceptions and deviations
Any deviations from Policy requirements must be approved in writing by ▸ [CISO / Board], documented and time-limited. The exceptions register is maintained by ▸ [CISO / relevant department].
7. Communication, Implementation and Training
This Policy is:
- Made available to all employees via ▸ [intranet / HR system / internal portal],
- Discussed during induction training for new employees,
- Confirmed by signature or electronic acknowledgement by each employee min. once/year,
- Incorporated into contracts with suppliers and partners having access to the organisation's systems.
Details of the training programme in DOC-017.
8. Document Management and Reviews
8.1 Review cycle
This Policy is subject to review:
- Regularly, at least once every ▸ [12 months]max. 12 months – NIS2,
- After any significant security incident,
- Following significant organisational or technological changes,
- Following changes in legislation.
8.2 Change History
| Version | Date | Author | Description | Approved by |
|---|---|---|---|---|
| ▸ 1.0 | ▸ DD/MM/YYYY | ▸ First Last Name | ▸ Initial release | ▸ Board/CEO |
| ▸ | ▸ | ▸ | ▸ | ▸ |
8.3 Related Documents
| Document | Relationship |
|---|---|
| DOC-002 Risk Management Procedure | Elaboration of section 3.5 (risk principle) |
| DOC-003 Risk Register | Operational register of risks identified per DOC-002 |
| DOC-004 Roles & RACI | Detailed responsibility matrix for section 4 |
| DOC-005 Incident Policy | Implementation of the incident management area |
| DOC-008 Access Control | Implementation of principle 3.1 (least privilege) |
9. Approval
| Role | Name | Date | Signature |
|---|---|---|---|
| Document Owner (CISO) | ▸ [First Last Name] | ▸ DD/MM/YYYY | ____________________ |
| Approving authority (Board/CEO) | ▸ [First Last Name] | ▸ DD/MM/YYYY | ____________________ |