Information Security Policy Template UK
Information Security Policy Template (UK)
Approx. 6 pages · 15 sectionsBranded PDF + editable WordLast reviewed:
What is a information security policy and who needs one?
An information security policy sets the rules for protecting your organisation's information and systems: access control, passwords, devices, patching, backups, incidents and supplier security. Buyers ask for it whenever you will hold their data or connect to their systems, often alongside Cyber Essentials certification for central government work.
Covers access control, acceptable use, passwords, device security, incident management and supplier security. Many government contracts expect Cyber Essentials certification in addition to a written policy.
Why buyers ask for this
Buyers must keep their data and systems safe, so they commonly ask how you protect information. Many central government contracts that handle personal or sensitive information also require Cyber Essentials certification.
Who needs it
Any supplier handling buyer information or connecting to buyer systems.
Where it comes up in a PQQ, SQ or PSQ
Under the Procurement Act 2023, supplier selection uses the Procurement Specific Questionnaire (PSQ) plus each buyer's own conditions of participation and quality questions. Typical questions this policy supports:
- "Do you hold Cyber Essentials or Cyber Essentials Plus?" plus a request for your security policy
- Questions on how you meet UK GDPR Article 32 security requirements
- Security incident history and incident response arrangements
- – Cyber Essentials certification is often required for central-government contracts that handle personal or sensitive information
What's inside
The full information security policy runs to about 6 pages (including the branded cover and document control page) across 15 sections:
- Purpose
- Scope
- Roles & Responsibilities
- Acceptable Use of ICT & Systems
- Access Control & Passwords
- Devices, Encryption & Remote Working
- Email, Messaging & File Sharing
- Use of Personal Devices (BYOD)
- Removable Media & Printing
- Third-Party Systems & Integrations
- Information Security Incidents & Breaches
- Monitoring & Logging
- Training & Awareness
- Non-Compliance
- Review
Key points covered
- Scope and objectives
- Roles and responsibilities
- Access control and passwords/MFA
- Device and remote working security
- Acceptable use
- Incident management
- Supplier security
- Review
Every document carries your logo, company name, version number, approval signatory and next review date, in branded PDF plus editable Word.
UK legislation, standards and guidance it references
- UK GDPR (Art. 32 security)
- Computer Misuse Act 1990
- ISO/IEC 27001 (voluntary standard)
- Cyber Essentials (government-backed scheme often required in tenders)
Excerpt preview
[Your Company Ltd] (“the Company”) is committed to protecting the confidentiality, integrity and availability of information and systems used in the course of its business. The purpose of this Policy is to: This Policy applies to: This Policy should be read alongside:
Get your information security policy in minutes
£19.99 per policy, or £199 for all 39 policies. One-off payment.
Tender deadline this week? Download in 10 minutes.
How to adapt it
- Read every section and remove anything that doesn’t reflect how your organisation actually works.
- Complete the bracketed [ADAPT] prompts with your own arrangements, people and data.
- Have the policy approved and signed by a director or equivalent, and communicate it to staff.
- Keep evidence that you follow it, and review it by the date shown.
Information Security Policy FAQs
Does this give me Cyber Essentials?
No. Cyber Essentials is a separate certification scheme. A policy helps you document the controls it checks.
What are the Cyber Essentials technical controls?
NCSC's Cyber Essentials covers five controls: firewalls, secure configuration, user access control, malware protection and security update management. The policy sets out rules in each area that support an assessment.
Should the policy cover remote and home working?
Yes. It sets rules for device security, secure Wi-Fi, screen locking and handling printed documents at home, which buyers increasingly ask about.
How much does the Information Security Policy template cost?
£19.99 per policy, or £199 for all 39 policies. It is a one-off payment with no subscription, and you download branded PDF and editable Word files straight away.
Free guides
- Which policies do UK public-sector tenders ask for?
- Procurement Specific Questionnaire (PSQ) explained for suppliers
General information, not legal advice. Requirements differ between buyers and change over time; always check the tender documents.