GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

GOV-001 Information Security Policy

Tier 1+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

A documented information security policy exists, has been approved by management, communicated to all personnel, and is reviewed at defined intervals and upon significant changes. The policy establishes the organisation's direction, scope, and commitment to protecting information assets.

Rationale

A formally approved and communicated policy is the foundation for all information security controls. Without it, there is no organisational baseline against which compliance and deviation can be measured.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
HIPAA Business Associate (US)stablerequiredrole duty

New row, from item 14 of the section 2 list in docs/s7-hipaa-proposals.md. 164.316(a) is a coverage test against an external instrument: every standard and implementation specification of the subpart traces to the policy or procedure that implements it, or to a 164.306(d)(3) determination. GOV-001 requires the policy to exist, be approved, be communicated and be reviewed, and holds this row as a partial because it states no trace. GOV-010 records that the obligation exists and GOV-024 that the procedures are available and kept current; neither maps a requirement to the procedure that answers it. The same gap sits on the GOV-024 row of this profile, whose note the lead may want to extend with the pointer.

NIS2 Cloud Provider (EU)stablerequiredrole duty

Annex point 1.1.1 of Implementing Regulation (EU) 2024/2690 fixes eleven contents for the policy, of which seven are not in the control: the commitment to continual improvement, the commitment to the resources needed for implementation, acknowledgement by relevant interested external parties, the list of documentation kept with its retention duration, the list of the topic-specific policies, indicators and measures of implementation and maturity, and the date of formal approval by the management bodies. Point 1.1.2 fixes the review at at least annually and hands it to the management bodies.

Framework Mappings (16)

GRC-01Governance Program Policy and Procedurespartial
GRC-03Organizational Policy Reviewspartial
GRC-01Governance Program Policy and Proceduresfull
GRC-03Organizational Policy Reviewspartial
GDPR-Art.24Controller Responsibility and Demonstrable Complianceinformative
HIPAA-164.308.a.1.iSecurity Management Processinformative
HIPAA-164.316.aPolicies and Procedurespartial
5.1Policies for information securityfull
NIS2-Art.20.1Management Body Approval and Oversight of Cybersecurity Measuresinformative
NIS2-Art.21.2.aPolicies on Risk Analysis and Information System Securitypartial
NIS2-CIR-1.1Policy on the Security of Network and Information Systemspartial
PL-1Policy and Procedurespartial
SC-1Policy and Procedurespartial
SI-1Policy and Procedurespartial
CC2.2COSO Principle 14: Communicates Internallypartial
CC5.3COSO Principle 12: Deploys Through Policies and Procedurespartial

Evidence (2)

policydocumentmanual

Information security policy document, management-approved, with revision date and distribution record.

Example: Information Security Policy v2.3 (Confluence page or Google Drive doc), showing named approver (e.g. CISO), approval date, and a distribution record such as an all-staff email or intranet announcement.

Test: Request the current information security policy document. Verify: (1) a named approver and approval date appear on the document and the date is within the last 12 months, (2) a defined scope statement is present, (3) evidence of distribution exists, confirmed via email send record, intranet post, or signed acknowledgement log.

recorddocumentmanual

Management review record showing the information security policy was formally reviewed at the most recent scheduled interval.

Example: Management review meeting minutes (Google Doc or Confluence) or a completed policy review workflow ticket (Jira/ServiceNow) dated within the last 12 months, with a named reviewer and disposition (approved / revised).

Test: Request the most recent policy review record. Verify: (1) review occurred within the defined interval (typically 12 months), (2) a named reviewer or approver is recorded, (3) if changes were made, a new version exists with updated approval date.

Questions (2)

boolean

Does your organisation have a documented information security policy that has been approved by senior management?

The policy should carry a named approver (e.g. CISO or CEO), an approval date within the last 12 months, and a defined scope statement.

select

How frequently is your information security policy formally reviewed and re-approved?

At least annuallyEvery 2 yearsOnly when significant changes occurAd hoc / no fixed scheduleNever formally reviewed

ISO 27001 and SOC 2 expect at minimum an annual review. Look for a review record (meeting minutes or a workflow ticket) dated within the required interval.