IS-01 Cyber security policy A documented Cyber Security Policy (or set of policies) MUST be in place and approved by senior management [P1] An information security policy is the foundation of an Organisation’s security programme. It sets out how the Organisation protects information assets, considering: Confidentiality: the protection of information from unauthorised access; Integrity: ensuring that information is complete and accurate and hasn’t been tampered with, altered or damaged in an unauthorised way; Availability: information is available to the right people when it is needed. The policy to be approved and signed off by senior management to demonstrate their commitment to the Organisation’s security programme. Cyber security policies MUST be kept up to date and effectively communicated to all relevant personnel. [P1] Policies to be reviewed regularly to make sure that they are suitable, adequate and effective for the Organisation. Policies to be communicated regularly to ever...