GOV-001 Information Security Policy
Description
A documented information security policy exists, has been approved by management, communicated to all personnel, and is reviewed at defined intervals and upon significant changes. The policy establishes the organisation's direction, scope, and commitment to protecting information assets.
Rationale
A formally approved and communicated policy is the foundation for all information security controls. Without it, there is no organisational baseline against which compliance and deviation can be measured.
Applicability (9 profiles)
New row, from item 14 of the section 2 list in docs/s7-hipaa-proposals.md. 164.316(a) is a coverage test against an external instrument: every standard and implementation specification of the subpart traces to the policy or procedure that implements it, or to a 164.306(d)(3) determination. GOV-001 requires the policy to exist, be approved, be communicated and be reviewed, and holds this row as a partial because it states no trace. GOV-010 records that the obligation exists and GOV-024 that the procedures are available and kept current; neither maps a requirement to the procedure that answers it. The same gap sits on the GOV-024 row of this profile, whose note the lead may want to extend with the pointer.
Annex point 1.1.1 of Implementing Regulation (EU) 2024/2690 fixes eleven contents for the policy, of which seven are not in the control: the commitment to continual improvement, the commitment to the resources needed for implementation, acknowledgement by relevant interested external parties, the list of documentation kept with its retention duration, the list of the topic-specific policies, indicators and measures of implementation and maturity, and the date of formal approval by the management bodies. Point 1.1.2 fixes the review at at least annually and hands it to the management bodies.
Framework Mappings (16)
| GRC-01 | Governance Program Policy and Procedures | partial |
| GRC-03 | Organizational Policy Reviews | partial |
| GRC-01 | Governance Program Policy and Procedures | full |
| GRC-03 | Organizational Policy Reviews | partial |
| GDPR-Art.24 | Controller Responsibility and Demonstrable Compliance | informative |
| HIPAA-164.308.a.1.i | Security Management Process | informative |
| HIPAA-164.316.a | Policies and Procedures | partial |
| 5.1 | Policies for information security | full |
| NIS2-Art.20.1 | Management Body Approval and Oversight of Cybersecurity Measures | informative |
| NIS2-Art.21.2.a | Policies on Risk Analysis and Information System Security | partial |
| NIS2-CIR-1.1 | Policy on the Security of Network and Information Systems | partial |
| PL-1 | Policy and Procedures | partial |
| SC-1 | Policy and Procedures | partial |
| SI-1 | Policy and Procedures | partial |
| CC2.2 | COSO Principle 14: Communicates Internally | partial |
| CC5.3 | COSO Principle 12: Deploys Through Policies and Procedures | partial |
Evidence (2)
Information security policy document, management-approved, with revision date and distribution record.
Example: Information Security Policy v2.3 (Confluence page or Google Drive doc), showing named approver (e.g. CISO), approval date, and a distribution record such as an all-staff email or intranet announcement.
Test: Request the current information security policy document. Verify: (1) a named approver and approval date appear on the document and the date is within the last 12 months, (2) a defined scope statement is present, (3) evidence of distribution exists, confirmed via email send record, intranet post, or signed acknowledgement log.
Management review record showing the information security policy was formally reviewed at the most recent scheduled interval.
Example: Management review meeting minutes (Google Doc or Confluence) or a completed policy review workflow ticket (Jira/ServiceNow) dated within the last 12 months, with a named reviewer and disposition (approved / revised).
Test: Request the most recent policy review record. Verify: (1) review occurred within the defined interval (typically 12 months), (2) a named reviewer or approver is recorded, (3) if changes were made, a new version exists with updated approval date.
Questions (2)
Does your organisation have a documented information security policy that has been approved by senior management?
The policy should carry a named approver (e.g. CISO or CEO), an approval date within the last 12 months, and a defined scope statement.
How frequently is your information security policy formally reviewed and re-approved?
ISO 27001 and SOC 2 expect at minimum an annual review. Look for a review record (meeting minutes or a workflow ticket) dated within the required interval.