From the course: ISO 27001:2022-Compliant Cybersecurity: Getting Started

Unlock the full course today

Join today to access over 23,200 courses taught by industry experts.

Policy (Clause 5.2)

Policy (Clause 5.2)

- [Instructor] Your organization's information security policy is one of the most important documents required by ISO 27001. In this video, you'll learn what the information security policy is, and why it's important. You'll also learn how to communicate it, and make it available to your organization and other interested parties. Clause 5.2 is titled simply, Policy. It requires that the top management of your organization establish an information security policy that is appropriate to the purpose of your organization. This means your organization's information security policy needs to align with how your organization operates. Information security policies can vary widely, from organization to organization, because they are customized, based on how each organization protects their information. Some organizations may want to include all of their security policies in one big information security policy, creating a…

Contents