5-Leadership

ISO 27001 Clause 5.2 — Information Security Policy

← All guides

ISO 27001 Clause 5.2 — Information Security Policy

Clause 5.2 requires top management to establish an information security policy. The policy is the governing statement of the ISMS. Everything else in the system traces back to it, including the objectives set under Clause 6.2, the controls selected from Annex A, and the corrective actions taken under Clause 10.

What 5.2 Actually Requires

The standard specifies that the information security policy must be appropriate to the purpose of the organization, include or provide a framework for setting information security objectives, commit to satisfying applicable requirements, and commit to continual improvement of the ISMS. It must also be documented, communicated within the organization, and made available to interested parties as appropriate.

That last part, available to interested parties, means the policy or a summary of it can be shared with customers, regulators, or business partners who ask about your security posture. For a healthcare practice like Meridian, that means patients, business associates, and the state health department.

What This Looks Like for an SMB

A common mistake at the SMB level is treating the information security policy as a compliance checkbox: a long document full of technical language that nobody reads and nobody follows. That approach fails an ISO 27001 audit because an auditor will ask staff whether they are aware of the policy and what it means for their work.

The information security policy sits at the top of the policy hierarchy — the governing statement of intent from which sub-policies, standards, and procedures derive their authority. Understanding where this document fits in that hierarchy, and what belongs here versus what belongs in functional policies below it, is covered in Governance, Security Goals, and Privacy.

For a small organization, an effective information security policy is:

  • Short enough that someone will actually read it. One to two pages is appropriate for most SMBs
  • Written in plain language that a non-technical staff member can understand
  • Signed by the person at the top: the managing partner, the physician-owner, the CEO
  • Scoped to the ISMS boundary defined in Clause 4.3, covering the information assets and processes within scope, not the entire organization by default
  • Linked to the organization’s actual security objectives, not generic statements about protecting information
  • Reviewed at defined intervals and updated when something changes

The policy does not need to contain every control the organization runs. That level of detail belongs in specific sub-policies: access control policy, incident response policy, and acceptable use policy. The information security policy sits above those as the governing statement of intent.

The questions auditors actually ask

An auditor reviewing Clause 5.2 compliance will want to see the signed policy document, evidence that it was communicated to staff, and confirmation that staff are actually aware of it. They will ask management when the policy was last reviewed and what prompted any changes. They will check that the policy references the organization’s information security objectives and that those objectives are measurable. A commitment to “protect patient data” is not an objective. A commitment to “achieve and maintain MFA on all ePHI-accessible systems by Q3” is.

What an auditor will check

A signed, dated information security policy approved by top management. Evidence of communication to staff: email distribution, intranet posting, onboarding acknowledgment. A defined review cycle with records of prior reviews. Alignment between the policy statement and the organization’s documented ISMS scope and objectives. Availability of the policy or a summary to external interested parties on request.

Common gap: The policy exists and is signed but staff have never seen it. It was created during the implementation project and never communicated. An auditor who asks three staff members whether they are aware of the information security policy and what it requires of them will expose this immediately. Document existence without communication is a non-conformity (deficiency) under Clause 5.2(f).


What the Document Looks Like

The information security policy for an SMB does not need to be elaborate. It needs to be accurate, approved, communicated, and maintained. Below is an example of what that document looks like for Meridian Health Partners, a 22-person healthcare practice implementing an ISO 27001-aligned ISMS to meet patient data protection obligations under HIPAA and to satisfy the security requirements of its business associates.

Example Document
Meridian Health Partners LLC
Information Security Policy | Clause 5.2 | Version 1.0 | July 2026

Purpose

This policy establishes the information security commitments of Meridian Health Partners LLC and provides the governing framework for the organization’s Information Security Management System (ISMS). It applies to all workforce members, contractors, and third parties who access information assets within the ISMS scope.

Scope

This policy covers all systems, processes, and information assets involved in the storage, processing, and transmission of electronic protected health information (ePHI), including the athenahealth EHR platform, clinical and administrative workstations, network infrastructure, and business associate relationships. The ISMS scope is defined in the Scope Statement under Clause 4.3.

Information Security Objectives

Meridian Health Partners is committed to the following information security objectives for the current ISMS period:

  • Achieve and maintain multi-factor authentication on all systems that access ePHI by [date]
  • Complete a formal HIPAA Security Risk Analysis per NIST SP 800-30 and document risk treatment decisions by [date]
  • Ensure all workforce members complete annual HIPAA Security Rule awareness training with documented completion
  • Maintain a current Business Associate Agreement with all third parties who create, receive, maintain, or transmit ePHI on behalf of the practice
  • Conduct an annual internal ISMS review and management review with documented outcomes

Commitments

Meridian Health Partners is committed to satisfying applicable information security requirements, including the HIPAA Security Rule (45 CFR Parts 160 and 164), applicable state health information privacy laws, and the contractual security obligations of our business associate agreements. The organization is committed to the continual improvement of the ISMS through regular risk assessment, management review, and corrective action processes.

Responsibilities

All workforce members are responsible for complying with this policy and the supporting policies and procedures of the ISMS. The designated Information Security Officer is responsible for the implementation and maintenance of the ISMS. The Managing Partner retains ultimate accountability for the ISMS and approves material changes to this policy, the ISMS scope, and risk treatment decisions.

Review

This policy will be reviewed annually and following any significant change to the organization’s operating environment, regulatory obligations, or security posture. All revisions require approval by the Managing Partner.

Approval

Approved by: [Managing Partner Name]
Title: Managing Partner, Meridian Health Partners LLC
Date: [Date]
Next Review Date: [Date + 1 year]

Next in this series: Clause 5.3: Roles, Responsibilities and Authorities.

Tags:

Darnell Keith

Not sure where you stand on this?

A Gap Assessment or IAM Governance Assessment tells you exactly where the gaps are — and what to do about them, in order of what matters most.

Get in Touch
NAXS Labs
Logo
Compare items
  • Total (0)
Compare
0
Shopping cart