Information Security Policy for IS Auditors
The policy is the yardstick for most security tests. Here's what it must contain and how to audit it.
An information security policy is management's written statement of intent: why security matters to this organisation, what it protects, who is responsible and what happens when someone does not comply. Everything else in the security programme, from password rules to firewall configuration, should trace back to it.
For an IS auditor the policy is the first document to read and the yardstick for most later tests. A control that exists but has no policy behind it is fragile; a policy with no controls behind it is a paper exercise. Both are findings.
You save ₹450
- Full-length timed mocks
- Module-wise practice
- Emerging-tech coverage
One payment, no subscription · Valid for 2 months
Policy, Standard, Procedure, Guideline
The ISA 3.0 material sets out a hierarchy. Exam questions often turn on which document is mandatory and which is advisory.
Policy
What it is
Management's high-level intent and direction, based on risk assessment
Mandatory?
Yes
Example
All information is classified and protected according to its value
Standard
What it is
Specific rules that implement the policy
Mandatory?
Yes
Example
Passwords at least a set length, changed on a defined cycle, locked after failed attempts
Procedure
What it is
Step-by-step activities to carry out a standard
Mandatory?
Yes
Example
How the helpdesk resets a locked SAP user after verifying identity
Guideline
What it is
Recommended practice to help apply the policy
Mandatory?
No, but strongly recommended
Example
Tips for choosing a memorable passphrase
| Document | What it is | Mandatory? | Example |
|---|---|---|---|
| Policy | Management's high-level intent and direction, based on risk assessment | Yes | All information is classified and protected according to its value |
| Standard | Specific rules that implement the policy | Yes | Passwords at least a set length, changed on a defined cycle, locked after failed attempts |
| Procedure | Step-by-step activities to carry out a standard | Yes | How the helpdesk resets a locked SAP user after verifying identity |
| Guideline | Recommended practice to help apply the policy | No, but strongly recommended | Tips for choosing a memorable passphrase |
What a Policy Should Contain
The components listed in the ISA 3.0 material, which line up with what RBI now requires banks to cover:
- checkPolicy statement and objective
- checkScope: which entities, locations, systems and people it covers
- checkOwnership, and roles and responsibilities, including an information security organisation structure
- checkThe business requirement for information security
- checkExceptions: how they are requested, approved, time-limited and recorded
- checkCompliance: how it is monitored, and penal measures for non-compliance
- checkPeriodic review, with a named reviewer and frequency
Supporting Policies You Will Meet
- check_circleData classification and privacy
- check_circleAcceptable use of information assets, usually signed by new joiners before access is given
- check_circlePhysical access and security
- check_circleAsset management
- check_circleNetwork security
- check_circlePassword and access control
- check_circleA separate cybersecurity policy, which RBI requires banks to keep distinct from the broader IT or information security policy so that cyber threats get their own strategy
Quick practice on audit concepts. No signup.
Auditing the Policy
Example: the statutory auditor's IT team at a mid-size listed manufacturer on SAP.
- 1
Approval and currency
Who approved it and when? For banks, RBI requires board approval of information security and cybersecurity policies, with review at least annually (the board may delegate review to the IT Strategy Committee). For others, check against the entity's own review cycle.
- 2
Alignment with risk
Does the policy reflect the latest risk assessment, or was it copied from a template? Look for systems or data the business now relies on that the policy does not mention.
- 3
Communication
Can staff show they received and accepted it? Signed acceptable use forms and awareness training records are the evidence.
- 4
Exceptions
Pull the exception register. A high number of approved, open exceptions signals the policy is not working.
- 5
Implementation
Sample standards and procedures and test that they enforce the policy, for example SAP password parameters against the password standard.
How the DISA Assessment Test Tests This
The ISA 3.0 chapter-end questions on this topic set the tone. Typical traps:
- check_circleThe best evidence of senior management commitment is their continuing involvement, such as information security as a standing item on their regular meeting agenda, rather than a bigger security budget or a directive to adopt a global standard.
- check_circleThe main reason to review a policy periodically is change in the environment, not a change in board members or new joiners.
- check_circleGuidelines are not mandatory. If an option calls a guideline a requirement, it is wrong.
- check_circleA high number of approved but still open policy exceptions is a compliance concern: exceptions are meant to be temporary and closed to a plan.
FAQs
What is the difference between a policy, a standard and a procedure?expand_more
A policy states management's intent. A standard sets the specific mandatory rules that implement it. A procedure is the step-by-step method for carrying out the standard. Guidelines are advisory only.
Who should approve the information security policy?expand_more
Senior management, and in regulated entities the board. RBI requires commercial banks' boards to approve information security and cybersecurity policies.
How often should an information security policy be reviewed?expand_more
At a defined interval and whenever the environment changes materially. For commercial banks, RBI sets at least annually.
Does ISO 27001 require an information security policy?expand_more
Yes. Clause 5.2 of ISO/IEC 27001:2022 covers the policy, and control 5.1 in ISO/IEC 27002:2022 covers policies for information security.
Next steps
- ISO 27001arrow_forward
- IT Committeesarrow_forward
- Logical Accessarrow_forward
- IT Risk Managementarrow_forward
Assessment Test format, timed and scored.
