Your country

Tools that support it use your country for local currency, number formats, units and paper size. Your choice is saved only in this browser.

Type a name or a two-letter code. Use the up and down arrow keys to move through the countries, Enter to choose one and Escape to close.

Information Security Policy Generator (ISO 27001 & SOC 2)

Up to 14 security policies written around how your organisation actually works.

Security No upload Free preview, no sign-upIncluded in your pass Premium tool Premium pass: ₹799 for 30 days

Free preview.

  • Free preview: every page with your details, the first part of the wording readable and the rest hidden, marked “MySmartCoPilot preview · not for use”.
  • Locked until you unlock it: download, copy and print.
  • Unlock: Premium pass, ₹799 for 30 days, a one-time payment that never renews.

Ways to unlock shows how to get the full result.

See passes (opens in a new tab)

Printing this result is locked in the free preview.

Pack preview

Your organisation

How you work

These answers decide which statements and policies the pack contains.

Also true for you

Roles

Job titles, as they should read after “the” in a sentence. Small organisations often give several of these roles to one person.

Numbers in the policies

Suggested values: change them to what you can actually meet. Auditors test what the policies say.

Document control and branding

The defaults for every policy; each policy can have its own owner, version and dates under “Policies in the pack”.

Logo PNG, JPEG or WebP, on the cover

Policies in the pack

  1. The top-level policy: commitment, objectives, roles, the topic policies, training, reporting and review.

    Owner, version and history

    Version history

    Left empty, the policy shows one row: its version, its approval date and “First issue”.

    1. How people may use information, accounts, e-mail, the internet and devices, at the office and away from it.

      Owner, version and history

      Version history

      Left empty, the policy shows one row: its version, its approval date and “First issue”.

      1. Least privilege, approvals, leavers, multi-factor authentication, privileged and supplier access, reviews, networks.

        Owner, version and history

        Version history

        Left empty, the policy shows one row: its version, its approval date and “First issue”.

        1. The inventory and its owners, licences, removable media, return of assets and secure disposal.

          Owner, version and history

          Version history

          Left empty, the policy shows one row: its version, its approval date and “First issue”.

          1. When encryption is required, acceptable algorithms and protocols, key and certificate management.

            Owner, version and history

            Version history

            Left empty, the policy shows one row: its version, its approval date and “First issue”.

            1. What is backed up and how often, protected and separate copies, retention and restore tests.

              Owner, version and history

              Version history

              Left empty, the policy shows one row: its version, its approval date and “First issue”.

              1. Recording, testing and approving changes, secure configurations, procedures, emergency changes, updates.

                Owner, version and history

                Version history

                Left empty, the policy shows one row: its version, its approval date and “First issue”.

                1. Security requirements, secure design and coding, code review, testing, test data and outsourced development.

                  Owner, version and history

                  Version history

                  Left empty, the policy shows one row: its version, its approval date and “First issue”.

                  1. The supplier register, checks before signing, security terms, cloud services, reviews and exit.

                    Owner, version and history

                    Version history

                    Left empty, the policy shows one row: its version, its approval date and “First issue”.

                    1. Impact analysis, recovery objectives, continuity and recovery plans, resilience, security during disruption, tests.

                      Owner, version and history

                      Version history

                      Left empty, the policy shows one row: its version, its approval date and “First issue”.

                      1. Four classification levels, labelling, handling rules, personal and card data, retention, masking and transfer.

                        Owner, version and history

                        Version history

                        Left empty, the policy shows one row: its version, its approval date and “First issue”.

                        1. Events to log, protected central logs, retention, clock synchronisation, alerts and their review.

                          Owner, version and history

                          Version history

                          Left empty, the policy shows one row: its version, its approval date and “First issue”.

                          1. Premises and entry, visitors, server rooms, environmental protection, clear desk, maintenance and disposal.

                            Owner, version and history

                            Version history

                            Left empty, the policy shows one row: its version, its approval date and “First issue”.

                            1. Screening, terms of employment and confidentiality, training, discipline, role changes and leavers.

                              Owner, version and history

                              Version history

                              Left empty, the policy shows one row: its version, its approval date and “First issue”.

                              Checks

                                Pack preview

                                Next steps

                                For general information only, not legal advice. Templates are generic starting points — have a qualified lawyer review anything you rely on.

                                About the Information Security Policy Generator (ISO 27001 & SOC 2)

                                The first thing an auditor asks for in an ISO/IEC 27001 or SOC 2 project is usually the policy set. This generator writes it from a short interview about your organisation — its size, whether it runs on cloud services or its own servers, where people work, whether it develops software, takes card payments or holds health data, and who is responsible for what — so that each policy describes how you actually work rather than a generic company.

                                The pack has up to 14 policies: information security, acceptable use, access control, asset management, cryptography, backup, change management, secure development, supplier security, business continuity, data classification and handling, logging and monitoring, physical security and HR security. Each one has a document control block, numbered statements you can refer to, the ISO/IEC 27001:2022 Annex A controls and SOC 2 Trust Services Criteria it supports, the related NIST references and a version history. A document register and a coverage table show which Annex A controls the pack addresses and which still need other documents. The wording is MySmartCoPilot’s own, built on public-domain NIST guidance; no ISO or AICPA text is reproduced.

                                The free preview shows every page as you build it, with most of the policy wording hidden; the PDF and Word files need a Premium pass. Nothing you enter is uploaded.

                                How to use it

                                1. Describe the organisation and How you work: your systems, where people work, personal devices, software development, card payments and the data you hold. These answers decide which statements, and which policies, the pack contains.
                                2. Enter the job titles under Roles and check the Numbers in the policies (how fast security updates are applied, when unused accounts are disabled, how long logs are kept, how often restores are tested), so that every commitment is one you can meet.
                                3. Set the document control defaults (ID prefix, version, approval date, approver and review cycle) and, under Policies in the pack, untick what you do not need and give any policy its own owner and version history.
                                4. Read the pack in the preview beside the form and fix what the Checks list. With a Premium pass, download the PDF pack, the Word pack, a ZIP of separate Word files with the register as a spreadsheet, or Markdown, or copy or print it; without one, the free preview shows every page with most of the wording hidden.
                                5. Use Save answers to keep a file of your answers and open it again at the next review: that works with or without a pass.

                                Examples

                                A software company of about 40 people
                                Input
                                Example answers: cloud services only, hybrid work, its own developers, card payments through a payment provider, personal data of customers
                                Result
                                14 policies on 54 A4 pages with the ID prefix EA-POL, a register and a coverage table: 83 of the 93 Annex A controls and 31 SOC 2 criteria supported; A.5.24 to A.5.27 are left to the incident response plan, and the server-room controls do not apply.

                                Press Example answers on the page.

                                A clinic on its own servers
                                Input
                                Own servers, office only, health information, no software development
                                Result
                                13 policies: server rooms, environmental protection and off-site backup copies appear, health information is Restricted and always encrypted, and the Secure Development Policy is left out.

                                Common uses

                                • A company starting an ISO/IEC 27001 certification or a SOC 2 examination.
                                • Answering a customer’s security questionnaire that asks for the policy set.
                                • Replacing scattered or outdated policies with one consistent, controlled pack.
                                • A consultant preparing a first draft of a client’s policies to review with them.

                                What each policy covers

                                • Information Security Policy: management direction, objectives, roles, segregation of duties, the topic policies, training, reporting and review.
                                • Acceptable Use: accounts, e-mail and the internet, devices, personal devices and remote working.
                                • Access Control: least privilege, approvals, leavers, multi-factor authentication, privileged, service and supplier accounts, access reviews and networks.
                                • Asset Management: the inventory and owners, licences, removable media, malware protection, return and secure disposal.
                                • Cryptography: when to encrypt, acceptable algorithms and protocols, keys and certificates.
                                • Backup: what is backed up, separate and immutable copies, retention and restore tests.
                                • Change Management: the change process, secure configuration, operating procedures, emergency changes and the times for security updates.
                                • Secure Development (when you build software): requirements, design, coding, review, testing, test data and outsourced development.
                                • Supplier Security: the supplier register, checks before signing, contract terms, cloud services, reviews and exit.
                                • Business Continuity: impact analysis, recovery objectives, plans, resilience and tests.
                                • Data Classification and Handling: four levels with examples, a handling table, personal and card data, retention, masking and transfer.
                                • Logging and Monitoring: what is logged, protected central logs, retention, clocks and alerts.
                                • Physical Security: premises, visitors, equipment rooms, clear desk, maintenance and disposal.
                                • Human Resources Security: screening, terms and confidentiality, training, discipline, role changes and leavers.

                                How your answers change the policies

                                • Cloud or own servers: server rooms, environmental protection and off-site copies appear only when you run your own equipment; on cloud services only, the physical security of data centres is checked through the providers’ assurance reports.
                                • Where people work: hybrid and remote work add rules for working away from the office and the matching Annex A control.
                                • Personal devices: not allowed, managed work apps only, or allowed once set up securely.
                                • Software development: adds the Secure Development Policy, source-code access and code review; outsourcing adds supplier terms for development.
                                • Card payments and health data: card numbers are kept out of your systems or protected as the PCI DSS requires, and health information becomes Restricted.
                                • Size: a small organisation may combine roles; a larger one gets a change advisory group, CCTV and phishing simulations.

                                Mapped to ISO 27001, SOC 2 and NIST

                                Every policy ends with the ISO/IEC 27001:2022 Annex A controls and the SOC 2 Trust Services Criteria it supports, the NIST Cybersecurity Framework 2.0 categories it relates to, and the NIST SP 800-53 Rev. 5 controls that NIST’s own crosswalk relates to those Annex A controls. The coverage table at the front collects them, so you can see which controls the pack addresses before you write the Statement of Applicability.

                                The mapping to Annex A and SOC 2 is MySmartCoPilot’s editorial judgement. A policy states what you intend; an auditor also wants evidence that it is followed, such as access reviews, change tickets and training records.

                                Incident response and passwords

                                Two policies are documents of their own and the pack refers to them: the incident response plan, which you can build with the Incident Response Plan Generator, and your password policy. The Access Control and Acceptable Use policies point to both.

                                Sources

                                Limitations

                                • Generic templates filled in from your answers, not legal advice: they do not decide which laws apply to you. Have them reviewed before you adopt them.
                                • A policy is not evidence that a control works: auditors also test records, configurations and samples.
                                • The mapping to Annex A and SOC 2 is MySmartCoPilot’s editorial judgement; your auditor decides whether a control meets a requirement.
                                • Written in English. The PDF draws Latin, Greek and Cyrillic text; for names in scripts that need shaping, such as Devanagari or Arabic, use the Word files.
                                • The incident response plan and the password policy are separate documents.

                                Privacy

                                Your answers and your logo stay in this browser and are never uploaded. Keep these answers in this browser is off unless you switch it on, so a draft is not left on a shared computer; Save answers gives you a file to keep instead.

                                Frequently asked questions

                                What do I get without a pass?

                                Without a pass, Information Security Policy Generator (ISO 27001 & SOC 2) shows every page with your details, the first part of the wording readable and the rest hidden, marked “MySmartCoPilot preview · not for use”. Until you unlock it, the result can’t be downloaded, copied or printed. A Premium pass, a one-time payment that never renews, unlocks the full result. The pricing page lists the passes and their prices.

                                Are these policies enough for ISO 27001 certification?

                                No set of documents is enough by itself. ISO/IEC 27001 also expects a risk assessment, a Statement of Applicability, objectives, internal audits and a management review, and the certification body checks that the controls work in practice. The policies cover the policy layer and point to the rest; the Information Security Risk Assessment and the Statement of Applicability Generator build two of those pieces.

                                Can we change the wording?

                                Yes. The Word files open in any word processor. For the next review it is usually quicker to open your saved answers here, change them and make the pack again, and to note your own edits in the version history.

                                Why do the policies not quote ISO 27001?

                                ISO sells the text of its standards. The policies use the control numbers and names, which is how auditors refer to them, with MySmartCoPilot’s own wording built on public-domain NIST guidance.

                                Who should own each policy?

                                Usually the security lead owns most of them, the IT lead the operational ones (assets, backup, change, logging and physical security) and the HR lead the HR policy, while top management approves them. Change any owner under Policies in the pack.

                                Where are my answers kept?

                                Only in this page while it is open, unless you switch on Keep these answers in this browser or save the answers file. Nothing is sent to a server.

                                Quick answers and tool search

                                Type to search tools or to get a quick answer, for example 18% of 2500. Use the up and down arrow keys to move through the results, Enter to choose, and Escape to close.