Skip to content

Master policy

Information Security Policy

The master policy. Sets out how the business protects information — and connects to every other policy below.

This is the policy every other one refers back to. Keep it short, owned, and reviewed annually. The version below is a working starter — edit the bracketed placeholders, drop in your specifics, and circulate.

How to use this: The bracketed items like [Company Name] are placeholders — replace them with your own details. Edit the wording to suit your business. This is a starter, not legal advice.

Purpose

This policy sets out how [Company Name] keeps its information and systems secure. The aim is to protect customer trust, comply with the law, support business continuity, and reduce the cost of getting it wrong.

Scope

It applies to every employee, contractor, intern, and authorised third party who handles [Company Name] information — on any device, in any location.

Principles

  1. Information is a business asset and is protected accordingly.
  2. Access is granted on a need-to-know basis only.
  3. Risks are identified, assessed, and managed proactively.
  4. Incidents are reported quickly and learned from.
  5. Compliance with UK GDPR, the Data Protection Act 2018, and customer contracts is mandatory.

Roles and responsibilities

  • The Board owns information risk and reviews it at least annually.
  • [Named Director] is the senior responsible owner.
  • [Named Manager] runs day-to-day implementation and reporting.
  • Every employee is responsible for following this policy and reporting concerns promptly.

Linked policies

Breach of policy

Suspected breaches must be reported to [Named Manager] within 24 hours. Confirmed breaches may result in disciplinary action up to and including dismissal, and may be reported to the ICO, the police, or relevant regulators.

Review

This policy is reviewed at least annually, after any significant incident, or following a material change in the business or its technology.

Last reviewed: [date] · Approved by: [name, role]

Tips for adoption

  • Keep it to two sides of A4. Long policies don't get read.
  • Get a director to sign and date it visibly.
  • Reference this from the joiner pack — everyone reads it on day 1.