Information Security Policy Generator (ISO 27001 & SOC 2)
Up to 14 security policies written around how your organisation actually works.
Free preview.
- Free preview: every page with your details, the first part of the wording readable and the rest hidden, marked “MySmartCoPilot preview · not for use”.
- Locked until you unlock it: download, copy and print.
- Unlock: Premium pass, ₹799 for 30 days, a one-time payment that never renews.
Ways to unlock shows how to get the full result.
Printing this result is locked in the free preview.
Pack preview
Locked in the free preview. Opens the ways to unlock this result.
Locked in the free preview. Batch runs unlock with a pass.
Locked in the free preview. Query results unlock with a pass.
For general information only, not legal advice. Templates are generic starting points — have a qualified lawyer review anything you rely on.
About the Information Security Policy Generator (ISO 27001 & SOC 2)
The first thing an auditor asks for in an ISO/IEC 27001 or SOC 2 project is usually the policy set. This generator writes it from a short interview about your organisation — its size, whether it runs on cloud services or its own servers, where people work, whether it develops software, takes card payments or holds health data, and who is responsible for what — so that each policy describes how you actually work rather than a generic company.
The pack has up to 14 policies: information security, acceptable use, access control, asset management, cryptography, backup, change management, secure development, supplier security, business continuity, data classification and handling, logging and monitoring, physical security and HR security. Each one has a document control block, numbered statements you can refer to, the ISO/IEC 27001:2022 Annex A controls and SOC 2 Trust Services Criteria it supports, the related NIST references and a version history. A document register and a coverage table show which Annex A controls the pack addresses and which still need other documents. The wording is MySmartCoPilot’s own, built on public-domain NIST guidance; no ISO or AICPA text is reproduced.
The free preview shows every page as you build it, with most of the policy wording hidden; the PDF and Word files need a Premium pass. Nothing you enter is uploaded.
How to use it
- Describe the organisation and How you work: your systems, where people work, personal devices, software development, card payments and the data you hold. These answers decide which statements, and which policies, the pack contains.
- Enter the job titles under Roles and check the Numbers in the policies (how fast security updates are applied, when unused accounts are disabled, how long logs are kept, how often restores are tested), so that every commitment is one you can meet.
- Set the document control defaults (ID prefix, version, approval date, approver and review cycle) and, under Policies in the pack, untick what you do not need and give any policy its own owner and version history.
- Read the pack in the preview beside the form and fix what the Checks list. With a Premium pass, download the PDF pack, the Word pack, a ZIP of separate Word files with the register as a spreadsheet, or Markdown, or copy or print it; without one, the free preview shows every page with most of the wording hidden.
- Use Save answers to keep a file of your answers and open it again at the next review: that works with or without a pass.
Examples
Example answers: cloud services only, hybrid work, its own developers, card payments through a payment provider, personal data of customers
14 policies on 54 A4 pages with the ID prefix EA-POL, a register and a coverage table: 83 of the 93 Annex A controls and 31 SOC 2 criteria supported; A.5.24 to A.5.27 are left to the incident response plan, and the server-room controls do not apply.
Press Example answers on the page.
Own servers, office only, health information, no software development
13 policies: server rooms, environmental protection and off-site backup copies appear, health information is Restricted and always encrypted, and the Secure Development Policy is left out.
Common uses
- A company starting an ISO/IEC 27001 certification or a SOC 2 examination.
- Answering a customer’s security questionnaire that asks for the policy set.
- Replacing scattered or outdated policies with one consistent, controlled pack.
- A consultant preparing a first draft of a client’s policies to review with them.
What each policy covers
- Information Security Policy: management direction, objectives, roles, segregation of duties, the topic policies, training, reporting and review.
- Acceptable Use: accounts, e-mail and the internet, devices, personal devices and remote working.
- Access Control: least privilege, approvals, leavers, multi-factor authentication, privileged, service and supplier accounts, access reviews and networks.
- Asset Management: the inventory and owners, licences, removable media, malware protection, return and secure disposal.
- Cryptography: when to encrypt, acceptable algorithms and protocols, keys and certificates.
- Backup: what is backed up, separate and immutable copies, retention and restore tests.
- Change Management: the change process, secure configuration, operating procedures, emergency changes and the times for security updates.
- Secure Development (when you build software): requirements, design, coding, review, testing, test data and outsourced development.
- Supplier Security: the supplier register, checks before signing, contract terms, cloud services, reviews and exit.
- Business Continuity: impact analysis, recovery objectives, plans, resilience and tests.
- Data Classification and Handling: four levels with examples, a handling table, personal and card data, retention, masking and transfer.
- Logging and Monitoring: what is logged, protected central logs, retention, clocks and alerts.
- Physical Security: premises, visitors, equipment rooms, clear desk, maintenance and disposal.
- Human Resources Security: screening, terms and confidentiality, training, discipline, role changes and leavers.
How your answers change the policies
- Cloud or own servers: server rooms, environmental protection and off-site copies appear only when you run your own equipment; on cloud services only, the physical security of data centres is checked through the providers’ assurance reports.
- Where people work: hybrid and remote work add rules for working away from the office and the matching Annex A control.
- Personal devices: not allowed, managed work apps only, or allowed once set up securely.
- Software development: adds the Secure Development Policy, source-code access and code review; outsourcing adds supplier terms for development.
- Card payments and health data: card numbers are kept out of your systems or protected as the PCI DSS requires, and health information becomes Restricted.
- Size: a small organisation may combine roles; a larger one gets a change advisory group, CCTV and phishing simulations.
Mapped to ISO 27001, SOC 2 and NIST
Every policy ends with the ISO/IEC 27001:2022 Annex A controls and the SOC 2 Trust Services Criteria it supports, the NIST Cybersecurity Framework 2.0 categories it relates to, and the NIST SP 800-53 Rev. 5 controls that NIST’s own crosswalk relates to those Annex A controls. The coverage table at the front collects them, so you can see which controls the pack addresses before you write the Statement of Applicability.
The mapping to Annex A and SOC 2 is MySmartCoPilot’s editorial judgement. A policy states what you intend; an auditor also wants evidence that it is followed, such as access reviews, change tickets and training records.
Incident response and passwords
Two policies are documents of their own and the pack refers to them: the incident response plan, which you can build with the Incident Response Plan Generator, and your password policy. The Access Control and Acceptable Use policies point to both.
Sources
- NIST Cybersecurity Framework 2.0
- NIST SP 800-53 Rev. 5 and its crosswalk to ISO/IEC 27001:2022
- ISO/IEC 27001:2022, Annex A: control numbers and names only (ISO sells the text of the standard)
- AICPA: 2017 Trust Services Criteria (with revised points of focus)
Limitations
- Generic templates filled in from your answers, not legal advice: they do not decide which laws apply to you. Have them reviewed before you adopt them.
- A policy is not evidence that a control works: auditors also test records, configurations and samples.
- The mapping to Annex A and SOC 2 is MySmartCoPilot’s editorial judgement; your auditor decides whether a control meets a requirement.
- Written in English. The PDF draws Latin, Greek and Cyrillic text; for names in scripts that need shaping, such as Devanagari or Arabic, use the Word files.
- The incident response plan and the password policy are separate documents.
Privacy
Your answers and your logo stay in this browser and are never uploaded. Keep these answers in this browser is off unless you switch it on, so a draft is not left on a shared computer; Save answers gives you a file to keep instead.
Frequently asked questions
What do I get without a pass?
Without a pass, Information Security Policy Generator (ISO 27001 & SOC 2) shows every page with your details, the first part of the wording readable and the rest hidden, marked “MySmartCoPilot preview · not for use”. Until you unlock it, the result can’t be downloaded, copied or printed. A Premium pass, a one-time payment that never renews, unlocks the full result. The pricing page lists the passes and their prices.
Are these policies enough for ISO 27001 certification?
No set of documents is enough by itself. ISO/IEC 27001 also expects a risk assessment, a Statement of Applicability, objectives, internal audits and a management review, and the certification body checks that the controls work in practice. The policies cover the policy layer and point to the rest; the Information Security Risk Assessment and the Statement of Applicability Generator build two of those pieces.
Can we change the wording?
Yes. The Word files open in any word processor. For the next review it is usually quicker to open your saved answers here, change them and make the pack again, and to note your own edits in the version history.
Why do the policies not quote ISO 27001?
ISO sells the text of its standards. The policies use the control numbers and names, which is how auditors refer to them, with MySmartCoPilot’s own wording built on public-domain NIST guidance.
Who should own each policy?
Usually the security lead owns most of them, the IT lead the operational ones (assets, backup, change, logging and physical security) and the HR lead the HR policy, while top management approves them. Change any owner under Policies in the pack.
Where are my answers kept?
Only in this page while it is open, unless you switch on Keep these answers in this browser or save the answers file. Nothing is sent to a server.