ISO 27001 policy templates

22 free, editable security policies mapped to the 93 Annex A controls of ISO/IEC 27001:2022. 91 controls are documented by at least one policy; the 2 that are not are listed below with the reason.

Written for SOC 2, mapped to Annex A

The Policyseed policies were written against the SOC 2 Trust Services Criteria, for small SaaS companies that run on a cloud provider. SOC 2 and ISO 27001 ask about largely the same things (access, change, incidents, suppliers, encryption, people), so the same documents carry over well. This page shows how far.

Each Annex A control below is mapped to the policies whose statements or procedures actually address it. We read the policy text for every mapping rather than matching on topic names, and where a policy only partly covers a control the note says so. Control numbers and short names follow the 2022 edition; the one-line summaries are our own plain-English paraphrase, not the text of the standard, which you should get from ISO or your national standards body.

Coverage at a glance

91 of 93 controls (98%) have at least one policy that documents them.

ThemeControlsDocumented by a policyNot covered
5. Organizational37370
6. People880
7. Physical14122
8. Technological34340
All of Annex A93912

The 2 controls the set does not cover

These are physical controls that only matter if you operate your own premises: for a cloud-hosted company they usually sit with the hosting provider or the landlord. Each one still needs an answer in your Statement of Applicability: a policy line you add, or a justified exclusion.

  • 7.6 Working in secure areas. The policies assume no company-operated secure areas (no server rooms or data centres); the secure areas that hold production systems are the hosting provider's. If you operate one, add rules for working in it; otherwise record it as not applicable in your Statement of Applicability.
  • 7.12 Cabling security. Not covered. For a cloud-hosted company, cabling that carries production traffic belongs to the hosting provider, and office cabling usually to the landlord; record it as such in your Statement of Applicability, or add a line if you run your own office network cabling.

A further handful are covered thinly, mostly physical controls that a cloud-hosted company inherits from its hosting provider. They are flagged with a note in the tables below.

93 controls, built in your browser. Opens in Excel, Numbers or Google Sheets.

Which policies carry the most

PolicyAnnex A controls documented
Endpoint and Workstation Security Policy11: 7.7, 7.9, 7.10, 7.13, 7.14, 8.1, 8.7, 8.9, 8.12, 8.19, 8.23
Data Classification and Handling Policy10: 5.9, 5.10, 5.12, 5.13, 5.14, 5.34, 8.3, 8.11, 8.12, 8.33
Secure Software Development Policy10: 5.8, 5.21, 5.32, 8.25, 8.26, 8.27, 8.28, 8.29, 8.31, 8.33
Physical and Remote Work Security Policy10: 6.7, 7.1, 7.2, 7.3, 7.4, 7.5, 7.7, 7.8, 7.9, 7.11
Logging and Monitoring Policy9: 5.7, 5.25, 5.33, 5.37, 8.6, 8.11, 8.15, 8.16, 8.17
Network and Infrastructure Security Policy9: 5.23, 8.2, 8.9, 8.14, 8.20, 8.21, 8.22, 8.27, 8.31
Information Security Policy8: 5.1, 5.2, 5.4, 5.6, 5.31, 5.35, 5.36, 6.3
Access Control Policy8: 5.15, 5.16, 5.18, 6.5, 8.2, 8.3, 8.4, 8.18
Change Management Policy8: 5.3, 8.4, 8.9, 8.19, 8.29, 8.30, 8.31, 8.32
Human Resources Security Policy8: 5.4, 5.11, 6.1, 6.2, 6.3, 6.4, 6.5, 6.6
Incident Response Policy7: 5.5, 5.24, 5.25, 5.26, 5.27, 5.28, 6.8
Vendor and Third-Party Risk Management Policy7: 5.19, 5.20, 5.21, 5.22, 5.23, 6.6, 8.30
Asset Management Policy6: 5.9, 5.11, 5.32, 7.10, 7.14, 8.6
Acceptable Use Policy5: 5.10, 5.32, 6.7, 6.8, 8.12
Business Continuity and Disaster Recovery Policy5: 5.29, 5.30, 5.37, 7.5, 8.14
Data Retention and Disposal Policy4: 5.33, 7.10, 7.14, 8.10
Privacy and Data Protection Policy4: 5.5, 5.8, 5.34, 8.10
Authentication and Password Policy3: 5.16, 5.17, 8.5
Encryption and Key Management Policy3: 5.3, 5.14, 8.24
Vulnerability and Patch Management Policy3: 5.7, 8.8, 8.34
Backup and Recovery Policy2: 5.30, 8.13
Risk Assessment and Management Policy2: 5.35, 5.36

The Annex A controls list, with the policies that document each

5. Organizational controls (37)

Governance, asset and access rules, suppliers, incidents, continuity and legal obligations. The largest theme, and where most policy writing happens.

ControlNameIn plain EnglishPolicyseed policies
5.1Policies for information securityHave a top-level security policy and supporting topic policies, approved by management, communicated to staff and reviewed on a schedule.Information Security Policy
5.2Information security roles and responsibilitiesDecide who is responsible for which parts of security and write it down.Note: Every policy also has its own roles section.Information Security Policy
5.3Segregation of dutiesSplit conflicting duties between different people so one person cannot both make and approve a sensitive change.Note: Covered for code changes (author never approves) and key administration; there is no general segregation matrix.Change Management Policy
Encryption and Key Management Policy
5.4Management responsibilitiesManagement requires everyone to follow the security policies and backs that up with funding and example.Information Security Policy
Human Resources Security Policy
5.5Contact with authoritiesKnow which authorities (regulators, law enforcement) to contact and when, and keep that contact controlled.Incident Response Policy
Privacy and Data Protection Policy
5.6Contact with special interest groupsStay in touch with security forums, professional associations and similar groups.Information Security Policy
5.7Threat intelligenceCollect and analyse information about threats relevant to you and use it to adjust controls.Vulnerability and Patch Management Policy
Logging and Monitoring Policy
5.8Information security in project managementBuild security requirements into projects from the start rather than bolting them on later.Note: Covers product and feature work (threat models, privacy impact assessments); non-engineering projects are not addressed.Secure Software Development Policy
Privacy and Data Protection Policy
5.9Inventory of information and other associated assetsKeep an up-to-date list of information and the assets that hold or process it, each with an owner.Asset Management Policy
Data Classification and Handling Policy
5.10Acceptable use of information and other associated assetsWrite down and enforce the rules for how people may use information and company assets.Acceptable Use Policy
Data Classification and Handling Policy
5.11Return of assetsPeople and organisations hand back company assets when their employment or contract ends.Asset Management Policy
Human Resources Security Policy
5.12Classification of informationSort information into levels by how much harm its disclosure or loss would cause.Data Classification and Handling Policy
5.13Labelling of informationMark information and systems with their classification so people know how to handle them.Data Classification and Handling Policy
5.14Information transferHave rules for sending information inside and outside the company, by any channel.Data Classification and Handling Policy
Encryption and Key Management Policy
5.15Access controlSet rules for who may access information and systems, based on business and security needs.Access Control Policy
5.16Identity managementManage the full lifecycle of user and system identities, one identity per person.Access Control Policy
Authentication and Password Policy
5.17Authentication informationControl how passwords, keys and other credentials are issued, stored, reset and protected.Authentication and Password Policy
5.18Access rightsGrant, review, change and remove access rights through a defined, approved process.Access Control Policy
5.19Information security in supplier relationshipsManage the security risks that come from using suppliers' products and services.Vendor and Third-Party Risk Management Policy
5.20Addressing information security within supplier agreementsPut the security requirements that matter into each supplier's contract.Vendor and Third-Party Risk Management Policy
5.21Managing information security in the ICT supply chainManage the security risks further down the technology supply chain, such as sub-processors and software dependencies.Vendor and Third-Party Risk Management Policy
Secure Software Development Policy
5.22Monitoring, review and change management of supplier servicesKeep checking that suppliers deliver the agreed security, and manage changes to their service.Vendor and Third-Party Risk Management Policy
5.23Information security for use of cloud servicesHave a process for choosing, using, managing and leaving cloud services securely.Note: Cloud providers are handled as Tier 1 vendors with exit plans, and the cloud environment is secured by the network policy; there is no standalone cloud services policy.Vendor and Third-Party Risk Management Policy
Network and Infrastructure Security Policy
5.24Information security incident management planning and preparationPlan in advance how incidents will be handled: roles, procedures and communication.Incident Response Policy
5.25Assessment and decision on information security eventsAssess security events and decide whether each one is an incident.Incident Response Policy
Logging and Monitoring Policy
5.26Response to information security incidentsRespond to incidents following the documented procedures.Incident Response Policy
5.27Learning from information security incidentsUse what was learned from incidents to strengthen controls.Incident Response Policy
5.28Collection of evidenceIdentify, collect and preserve evidence about security events in a way that will stand up later.Incident Response Policy
5.29Information security during disruptionKeep security at an appropriate level while the business is disrupted.Business Continuity and Disaster Recovery Policy
5.30ICT readiness for business continuityPlan, build and test IT recovery so continuity objectives can actually be met.Business Continuity and Disaster Recovery Policy
Backup and Recovery Policy
5.31Legal, statutory, regulatory and contractual requirementsIdentify the laws, regulations and contract terms that affect security, record them, and keep the list current.Note: Statement 4.15 and procedure 5.9 keep a register of obligations; the privacy, retention and incident policies hold the specific obligations. Which laws apply is for you and your counsel to decide.Information Security Policy
5.32Intellectual property rightsRespect intellectual property, including software licences and open-source terms.Asset Management Policy
Acceptable Use Policy

Secure Software Development Policy
5.33Protection of recordsProtect records from loss, destruction, tampering and unauthorised access for as long as they are kept.Data Retention and Disposal Policy
Logging and Monitoring Policy
5.34Privacy and protection of PIIMeet the privacy and personal data protection requirements that apply to you.Privacy and Data Protection Policy
Data Classification and Handling Policy
5.35Independent review of information securityHave the security approach reviewed independently at planned intervals and after significant changes.Note: Annual independent evaluation of the risk process, plus the external SOC 2 examination. An ISMS internal audit (clause 9.2) is separate and not covered.Risk Assessment and Management Policy
Information Security Policy
5.36Compliance with policies, rules and standards for information securityCheck regularly that the company actually follows its own security policies and standards.Information Security Policy
Risk Assessment and Management Policy
5.37Documented operating proceduresWrite down operating procedures and make them available to the people who need them.Note: Recovery procedures and alert runbooks are required by these policies; each policy's section 5 is itself a procedure set. The day-to-day runbooks are yours to write.Business Continuity and Disaster Recovery Policy
Logging and Monitoring Policy

6. People controls (8)

What happens before, during and after someone works for you: screening, agreements, training, discipline and reporting.

ControlNameIn plain EnglishPolicyseed policies
6.1ScreeningCheck the background of candidates before they join, in proportion to the role and within the law.Human Resources Security Policy
6.2Terms and conditions of employmentEmployment and contractor agreements state each side's security responsibilities.Human Resources Security Policy
6.3Information security awareness, education and trainingGive staff security awareness and role-specific training when they join and regularly after.Human Resources Security Policy
Information Security Policy
6.4Disciplinary processHave a formal, communicated process for dealing with people who break security policy.Human Resources Security Policy
6.5Responsibilities after termination or change of employmentMake clear which security duties continue after someone leaves or changes role, and enforce them.Human Resources Security Policy
Access Control Policy
6.6Confidentiality or non-disclosure agreementsUse confidentiality agreements with staff and outside parties, and review them when needs change.Human Resources Security Policy
Vendor and Third-Party Risk Management Policy
6.7Remote workingProtect information that is accessed, processed or stored while working away from the office.Physical and Remote Work Security Policy
Acceptable Use Policy
6.8Information security event reportingGive staff a quick, simple way to report suspected security events, and expect them to use it.Incident Response Policy
Acceptable Use Policy

7. Physical controls (14)

Premises, equipment and media. For a company whose servers all live with a cloud provider, much of this theme is inherited from the provider.

ControlNameIn plain EnglishPolicyseed policies
7.1Physical security perimetersDefine and protect the physical boundaries around areas that hold information and equipment.Note: Data centre perimeters are delegated to the hosting provider and checked through its assurance report; office perimeters apply only where an office exists.Physical and Remote Work Security Policy
7.2Physical entryControl who can enter secure areas, using entry controls and visitor procedures.Physical and Remote Work Security Policy
7.3Securing offices, rooms and facilitiesDesign and apply physical security for offices, rooms and other facilities.Physical and Remote Work Security Policy
7.4Physical security monitoringWatch premises for unauthorised physical access, for example with alarms or surveillance.Note: Thin coverage: relies on the hosting provider's surveillance plus annual alarm tests and access-log reconciliation for any office. No CCTV requirement.Physical and Remote Work Security Policy
7.5Protecting against physical and environmental threatsProtect against fire, flood, power loss, natural disasters and other physical threats.Note: Environmental controls are the hosting provider's; multi-zone design limits the impact of a facility loss.Physical and Remote Work Security Policy
Business Continuity and Disaster Recovery Policy
7.6Working in secure areasSet rules for how people work inside designated secure areas.Note: The policies assume no company-operated secure areas (no server rooms or data centres); the secure areas that hold production systems are the hosting provider's. If you operate one, add rules for working in it; otherwise record it as not applicable in your Statement of Applicability.Not covered
7.7Clear desk and clear screenKeep papers and removable media off desks and lock screens when away.Physical and Remote Work Security Policy
Endpoint and Workstation Security Policy
7.8Equipment siting and protectionPlace and protect equipment so it is safe from physical threats and unauthorised viewing or access.Note: Covers device storage, screen privacy and locked network cabinets; server siting is the hosting provider's.Physical and Remote Work Security Policy
7.9Security of assets off-premisesProtect laptops and other assets taken outside company premises.Physical and Remote Work Security Policy
Endpoint and Workstation Security Policy
7.10Storage mediaManage storage media through its whole life: use, transport, reuse and disposal.Asset Management Policy
Endpoint and Workstation Security Policy

Data Retention and Disposal Policy
7.11Supporting utilitiesProtect equipment from failures of power, cooling and other supporting utilities.Note: Delegated to hosting providers (power and cooling) and verified through their assurance reports; no office utility controls.Physical and Remote Work Security Policy
7.12Cabling securityProtect power and data cables from interception, interference and damage.Note: Not covered. For a cloud-hosted company, cabling that carries production traffic belongs to the hosting provider, and office cabling usually to the landlord; record it as such in your Statement of Applicability, or add a line if you run your own office network cabling.Not covered
7.13Equipment maintenanceMaintain equipment properly so it stays available and its information stays protected.Note: Covers laptop repairs by the manufacturer or authorised service providers; servers and network hardware are maintained by the hosting provider.Endpoint and Workstation Security Policy
7.14Secure disposal or re-use of equipmentWipe or destroy data and software on equipment before it is reused or thrown away.Asset Management Policy
Data Retention and Disposal Policy

Endpoint and Workstation Security Policy

8. Technological controls (34)

Endpoints, identity, logging, networks, cryptography and the secure development of software.

ControlNameIn plain EnglishPolicyseed policies
8.1User endpoint devicesProtect information stored on, processed by or reachable from laptops, phones and other user devices.Endpoint and Workstation Security Policy
8.2Privileged access rightsRestrict, control and monitor the use of administrator and other privileged access.Access Control Policy
Network and Infrastructure Security Policy
8.3Information access restrictionLimit access to information and systems in line with the access control rules.Access Control Policy
Data Classification and Handling Policy
8.4Access to source codeControl read and write access to source code, development tools and software libraries.Access Control Policy
Change Management Policy
8.5Secure authenticationUse authentication methods, such as MFA, that fit the sensitivity of what is being accessed.Authentication and Password Policy
8.6Capacity managementMonitor resource use and plan capacity so systems keep performing as needed.Asset Management Policy
Logging and Monitoring Policy
8.7Protection against malwareProtect against malware with tools and with user awareness.Endpoint and Workstation Security Policy
8.8Management of technical vulnerabilitiesFind out about technical vulnerabilities, assess your exposure and fix them on time.Vulnerability and Patch Management Policy
8.9Configuration managementDefine secure configurations for hardware, software and networks, apply them and watch for drift.Network and Infrastructure Security Policy
Endpoint and Workstation Security Policy

Change Management Policy
8.10Information deletionDelete information when it is no longer needed.Data Retention and Disposal Policy
Privacy and Data Protection Policy
8.11Data maskingMask, pseudonymise or anonymise data where the full values are not needed.Data Classification and Handling Policy
Logging and Monitoring Policy
8.12Data leakage preventionTake measures to stop sensitive information leaking out of systems, networks and devices.Note: Handled through handling rules, removable-media blocking and quarterly exposure checks; no DLP tool is required.Data Classification and Handling Policy
Endpoint and Workstation Security Policy

Acceptable Use Policy
8.13Information backupTake backups of information and systems and test that they restore.Backup and Recovery Policy
8.14Redundancy of information processing facilitiesBuild in enough redundancy to meet availability requirements.Business Continuity and Disaster Recovery Policy
Network and Infrastructure Security Policy
8.15LoggingProduce, keep, protect and analyse logs of activity, errors and security events.Logging and Monitoring Policy
8.16Monitoring activitiesMonitor networks, systems and applications for unusual behaviour and act on it.Logging and Monitoring Policy
8.17Clock synchronizationSynchronise system clocks to a trusted time source so events line up across systems.Logging and Monitoring Policy
8.18Use of privileged utility programsRestrict and control tools that can override system and application controls.Access Control Policy
8.19Installation of software on operational systemsControl how software is installed on production and other operational systems.Change Management Policy
Endpoint and Workstation Security Policy
8.20Networks securitySecure and manage networks and network devices to protect the information on them.Network and Infrastructure Security Policy
8.21Security of network servicesIdentify the security features and service levels network services need, and make sure they are delivered.Network and Infrastructure Security Policy
8.22Segregation of networksSeparate groups of services, users and systems onto different networks or segments.Network and Infrastructure Security Policy
8.23Web filteringControl which external websites people can reach to reduce exposure to malicious content.Note: Browser safe-browsing protection on every endpoint, plus DNS or web filtering where the MDM supports it. There is no category-based blocking of websites.Endpoint and Workstation Security Policy
8.24Use of cryptographyDefine and follow rules for using cryptography, including key management.Encryption and Key Management Policy
8.25Secure development life cycleDefine and apply rules for developing software and systems securely.Secure Software Development Policy
8.26Application security requirementsIdentify and approve security requirements when building or buying applications.Secure Software Development Policy
8.27Secure system architecture and engineering principlesSet principles for designing secure systems and apply them to all system development.Secure Software Development Policy
Network and Infrastructure Security Policy
8.28Secure codingApply secure coding principles when writing software.Secure Software Development Policy
8.29Security testing in development and acceptanceDefine and run security tests during development and before release.Secure Software Development Policy
Change Management Policy
8.30Outsourced developmentDirect, monitor and review development work done by outside parties.Note: Contractors follow the same review and deployment process as staff; there is no dedicated outsourced-development clause.Change Management Policy
Vendor and Third-Party Risk Management Policy
8.31Separation of development, test and production environmentsKeep development, test and production environments separate and secured.Network and Infrastructure Security Policy
Secure Software Development Policy

Change Management Policy
8.32Change managementChanges to systems and information processing facilities go through a change management process.Change Management Policy
8.33Test informationChoose, protect and manage test data, avoiding real production data where possible.Data Classification and Handling Policy
Secure Software Development Policy
8.34Protection of information systems during audit testingPlan audits and technical tests of live systems so they do not disrupt operations.Vulnerability and Patch Management Policy

What ISO 27001 requires beyond the Annex A policies

Annex A is an appendix. The certifiable part of ISO 27001 is clauses 4 to 10, which describe an information security management system (ISMS): the way you decide what to protect, choose controls, and keep checking and improving them. Policies are one output of that system, not the system itself. In outline, and in our words:

  • Context and ISMS scope (clause 4). A written scope saying which parts of the organisation, locations, products and systems the ISMS covers, informed by the issues and interested parties (customers, regulators, suppliers) that matter to you.
  • Leadership (clause 5). Top management visibly owns the ISMS: approves the top-level policy, assigns roles and provides resources. The Information Security Policy covers the policy and roles; the commitment has to show up in records.
  • Planning (clause 6). A defined risk assessment method, a risk treatment plan, measurable security objectives, and the Statement of Applicability: all 93 Annex A controls, whether each is included or excluded, why, and whether it is implemented. The Risk Assessment and Management Policy gives you the method and register; the Statement of Applicability and treatment plan are separate documents.
  • Support (clause 7). Resources, competence of the people doing security work, awareness, communication, and control of documented information (versioning, approval and access to the documents themselves).
  • Operation (clause 8). Actually running the risk assessments and treatment plan on schedule and keeping the results.
  • Performance evaluation (clause 9). Monitoring and measurement, a planned internal audit programme covering the whole ISMS, and a periodic management review with defined inputs and recorded decisions.
  • Improvement (clause 10). Handling nonconformities with corrective actions, and showing the ISMS gets better over time.

A certification auditor will look at these records at least as closely as at the Annex A policies. The policies here give you a head start on the control side; the scope statement, Statement of Applicability, risk treatment plan, objectives, internal audit reports and management review minutes are yours to produce.

Who certifies you

ISO 27001 certification is issued by a certification body accredited by a national accreditation body (UKAS in the UK, ANAB in the US, and their equivalents elsewhere). The audit runs in two stages: a review of your ISMS documentation, then an assessment of whether it operates in practice. A certificate lasts three years, with surveillance audits in between. Policyseed is a template generator; it does not audit or certify anyone, and adopting these templates does not by itself mean an organisation meets the standard.

If you already have SOC 2

Most of the work carries over. The same policies serve both, and the evidence you collect for SOC 2 (access reviews, change records, incident logs, vendor reviews) is the evidence an ISO auditor samples too. The additions are the management-system records above and the uncovered controls on this page. For the SOC 2 side, see the SOC 2 controls list and the full security policy templates index.

Frequently asked questions

Are these ISO 27001 policy templates free?
Yes. The 22 policies are Apache-2.0 licensed, and you can read every one on this site or generate the full set edited for your company without signing up. The Annex A mapping on this page is free to download as a CSV.
How many policies does ISO 27001 require?
The standard requires one information security policy at the top (clause 5.2) and expects topic-specific policies where your risk assessment and Statement of Applicability call for them. There is no fixed number. Most small companies end up with somewhere between 10 and 25 documents; the 22 here are split by owner and review cadence so each one stays maintainable.
Do I need all 93 Annex A controls?
No. Annex A is a reference list you compare your risk treatment against. Every control must appear in your Statement of Applicability, but you may exclude a control if you justify why it does not apply, for example cabling security when you have no premises of your own. What you cannot do is leave a control out without saying why.
What changed between ISO 27001:2013 and 2022 Annex A?
The 2013 edition had 114 controls in 14 domains. The 2022 edition regrouped them into 93 controls in four themes (organizational, people, physical and technological), merged many of the old controls and added 11 new ones, including threat intelligence, cloud services, ICT readiness for business continuity, configuration management, data masking, data leakage prevention, web filtering and secure coding. Certificates against the 2013 edition expired at the end of the transition period in October 2025.
Can I use the same policies for SOC 2 and ISO 27001?
Yes, and most companies that need both do exactly that. The controls overlap heavily, so one policy set mapped to both frameworks is easier to maintain than two. ISO 27001 adds management-system requirements that SOC 2 does not ask for in the same form, such as the Statement of Applicability, internal audit and management review, and those need their own records.

ISO and ISO/IEC 27001 are standards published by the International Organization for Standardization and the International Electrotechnical Commission. Policyseed is not affiliated with either. Control names are cited for reference; the summaries are our own.

Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.