isms.coach
← All controls

A.5.1 · Organizational

Policies for information security

Why it matters

Auditors check this first — it's the top-level statement that everything else in your ISMS traces back to.

How a self-led small team implements it

One short, org-wide policy is enough at this stage; don't split it into a dozen sub-policies before you need to.

What auditors expect to see

Approved policy document, review date, who approved it.

Track A.5.1 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.

Start your ISMS

More organizational controls