companypolicies.aicompanypolicies.ai

Information Security Policy Template UK

Information Security Policy Template (UK)

Approx. 6 pages · 15 sectionsBranded PDF + editable WordLast reviewed:

What is a information security policy and who needs one?

An information security policy sets the rules for protecting your organisation's information and systems: access control, passwords, devices, patching, backups, incidents and supplier security. Buyers ask for it whenever you will hold their data or connect to their systems, often alongside Cyber Essentials certification for central government work.

Covers access control, acceptable use, passwords, device security, incident management and supplier security. Many government contracts expect Cyber Essentials certification in addition to a written policy.

Why buyers ask for this

Buyers must keep their data and systems safe, so they commonly ask how you protect information. Many central government contracts that handle personal or sensitive information also require Cyber Essentials certification.

Who needs it

Any supplier handling buyer information or connecting to buyer systems.

Where it comes up in a PQQ, SQ or PSQ

Under the Procurement Act 2023, supplier selection uses the Procurement Specific Questionnaire (PSQ) plus each buyer's own conditions of participation and quality questions. Typical questions this policy supports:

  • "Do you hold Cyber Essentials or Cyber Essentials Plus?" plus a request for your security policy
  • Questions on how you meet UK GDPR Article 32 security requirements
  • Security incident history and incident response arrangements
  • – Cyber Essentials certification is often required for central-government contracts that handle personal or sensitive information

What's inside

The full information security policy runs to about 6 pages (including the branded cover and document control page) across 15 sections:

  1. Purpose
  2. Scope
  3. Roles & Responsibilities
  4. Acceptable Use of ICT & Systems
  5. Access Control & Passwords
  6. Devices, Encryption & Remote Working
  7. Email, Messaging & File Sharing
  8. Use of Personal Devices (BYOD)
  9. Removable Media & Printing
  10. Third-Party Systems & Integrations
  11. Information Security Incidents & Breaches
  12. Monitoring & Logging
  13. Training & Awareness
  14. Non-Compliance
  15. Review

Key points covered

  • Scope and objectives
  • Roles and responsibilities
  • Access control and passwords/MFA
  • Device and remote working security
  • Acceptable use
  • Incident management
  • Supplier security
  • Review

Every document carries your logo, company name, version number, approval signatory and next review date, in branded PDF plus editable Word.

UK legislation, standards and guidance it references

Excerpt preview

[Your Company Ltd] (“the Company”) is committed to protecting the confidentiality, integrity and availability of information and systems used in the course of its business. The purpose of this Policy is to: This Policy applies to: This Policy should be read alongside:

Short excerpt. The full policy is generated with your details after purchase.

Get your information security policy in minutes

£19.99 per policy, or £199 for all 39 policies. One-off payment.

Tender deadline this week? Download in 10 minutes.

How to adapt it

  1. Read every section and remove anything that doesn’t reflect how your organisation actually works.
  2. Complete the bracketed [ADAPT] prompts with your own arrangements, people and data.
  3. Have the policy approved and signed by a director or equivalent, and communicate it to staff.
  4. Keep evidence that you follow it, and review it by the date shown.

Information Security Policy FAQs

Does this give me Cyber Essentials?

No. Cyber Essentials is a separate certification scheme. A policy helps you document the controls it checks.

What are the Cyber Essentials technical controls?

NCSC's Cyber Essentials covers five controls: firewalls, secure configuration, user access control, malware protection and security update management. The policy sets out rules in each area that support an assessment.

Should the policy cover remote and home working?

Yes. It sets rules for device security, secure Wi-Fi, screen locking and handling printed documents at home, which buyers increasingly ask about.

How much does the Information Security Policy template cost?

£19.99 per policy, or £199 for all 39 policies. It is a one-off payment with no subscription, and you download branded PDF and editable Word files straight away.

Free guides

General information, not legal advice. Requirements differ between buyers and change over time; always check the tender documents.

Tender deadline this week? Download in 10 minutes.

Create my policies · from £19.99