Information Security Policy template (SOC 2)

Establishes the information security program, its objectives, its governance and who is accountable for it.

Policy P01 of 22 · Owner: Security Owner · 10 criteria in the crosswalk · Apache-2.0

What this policy is for

The Information Security Policy is one of the 22 governance policies in the Policyseed set. It is owned by the Security Owner, approved by the executive you name in the intake, and reviewed on the cadence you choose. Like every policy in the set it has nine numbered sections: purpose, scope, roles, policy statements, procedures, exceptions, enforcement, review cadence and a revision history table. Sections 4 and 5 carry the substance; those are the sections the Audit Kit rewrites for your named tools.

SOC 2 criteria this policy addresses

The Policyseed crosswalk maps 10 criteria to this policy. Each row names the section an auditor would read for that criterion; the criterion pages explain what it asks in plain words and list evidence examples.

CriterionWhat it coversWhere in this policy
CC1.1Integrity and ethical valuesSection 4 (Policy Statements)
CC1.2Oversight by leadershipSection 3 (Roles and Responsibilities)
CC1.3Structure, reporting lines and authoritySection 3 (Roles and Responsibilities)
CC1.5AccountabilitySection 7 (Enforcement)
CC2.2Internal communicationSection 5 (Procedures)
CC3.1Objectives for risk assessmentSection 4 (Policy Statements)
CC4.1Ongoing and separate evaluationsSection 8 (Review Cadence)
CC4.2Communicating deficienciesSection 5 (Procedures)
CC5.1Selecting control activitiesSection 4 (Policy Statements)
CC5.3Policies and proceduresSection 5 (Procedures), Section 8 (Review Cadence)

Evidence auditors typically ask for

A policy is tested against artifacts. These are examples from the crosswalk for the criteria above, written for a small SaaS company; the Audit Kit ships the full list as an evidence checklist with an owner per row.

  • Signed Acceptable Use Policy acknowledgment forms for every employee and contractor
  • Employee handbook or code of conduct section referenced by the Information Security Policy
  • Approved Information Security Policy with the approver's name and effective date on the revision table
  • Leadership or board meeting notes showing a security update as an agenda item at least twice a year
  • Memo or email appointing the Security Owner, signed by the approver
  • Annual risk assessment summary presented to leadership with the date it was reviewed
  • Current org chart exported from the HR or identity system
  • Roles and Responsibilities section of the Information Security Policy naming the Security Owner, Engineering Lead and approver

Full text: the Information Security Policy rendered for Northwind Cloud Inc

Below is the complete template as the generator renders it for Northwind Cloud Inc, a fictional 11-50-person remote company running Northwind on AWS, Vercel, GitHub and Okta. Every name, tool and date comes from that sample intake; your answers replace them. Section headings carry anchors so the criterion pages can link straight to the section they cite.

Sample document

Northwind Cloud Inc Information Security Policy

1. Purpose

Northwind Cloud Inc builds and operates Northwind, and its customers trust it with their data. This policy establishes the information security program that protects that trust: what the program must achieve, who is accountable for it, and the rules that every other policy in this set builds on, so that security decisions at Northwind Cloud Inc are deliberate, written down and open to review.

2. Scope

This policy applies to all personnel of Northwind Cloud Inc, including employees, contractors, interns and temporary staff, and to every system, service and dataset used to build, deliver or support Northwind, including:

  • Production and non-production infrastructure on AWS and Vercel.
  • Source code and deployment tooling in GitHub and GitHub Actions.
  • Identity, authentication and access managed through Okta.
  • Laptops, phones and any other equipment used to reach company systems, enrolled in Kandji.
  • Third-party services that store or process company or customer data, currently including Supabase, Stripe, Datadog and Slack.

The cloud platforms in scope are:

  • AWS
  • Vercel

The Trust Services Criteria selected for the SOC 2 examination are Security and Availability. Because Availability is in scope, the program also covers the resilience and recovery of Northwind. Northwind Cloud Inc processes PII data for its customers, and the controls in this set are calibrated to that.

3. Roles and Responsibilities

  • Executive Management (Priya Natarajan, CEO) approves this policy and the annual security objectives, funds the program, receives a written security status report at least quarterly, and decides on risks that exceed the agreed tolerance.
  • Security Owner (Dana Whitfield, CTO) owns the program and this policy set, maintains the risk register and control matrix, approves exceptions, coordinates incident response, collects control evidence, and is the primary contact for the CPA firm.
  • Engineering designs, builds and operates Northwind and its infrastructure on AWS and Vercel in line with these policies. Engineering leads own the technical policies assigned to them in the policy register.
  • People Operations owns the personnel controls: background screening where lawful, onboarding and offboarding checklists, policy acknowledgement and training records.
  • All Personnel read and acknowledge the policies that apply to them, complete required training, follow the procedures in this set, and report suspected incidents or violations to security@northwindcloud.example without delay.

4. Policy Statements

  • 4.1 Northwind Cloud Inc maintains a written information security program consisting of this policy and the supporting policies in the policy register. Together they define the minimum security requirements for the company; where a supporting policy is more specific, it takes precedence.
  • 4.2 The program exists to protect the confidentiality, integrity and availability of customer data and company systems; to meet the commitments Northwind Cloud Inc makes in contracts, its terms of service and its privacy notice; to satisfy the Security and Availability criteria selected for the SOC 2 examination; and to keep risk within the tolerance set by Executive Management.
  • 4.3 Executive Management appoints a Security Owner with the authority to set security requirements, halt changes or releases that create unacceptable risk, and escalate directly to Executive Management. The appointment is documented in the role description of Dana Whitfield, CTO.
  • 4.4 Controls are selected and prioritised according to the risks they reduce, as recorded in the risk assessment maintained under the Risk Assessment and Management Policy, not solely because a framework lists them.
  • 4.5 Every policy in this set has a named owner role, an approver, a version number and an effective date, and is reviewed on the annual cycle and after any significant change to the business, the technology stack or the threat landscape.
  • 4.6 All personnel acknowledge this policy and the Acceptable Use Policy in writing at hire, at each annual review and after each material revision. Acknowledgements are retained as evidence.
  • 4.7 Security awareness training is completed within thirty days of the start date and annually thereafter. Engineers also complete secure development training under the Secure Software Development Policy.
  • 4.8 Access follows least privilege and is granted by role under the Access Control Policy. Multi-factor authentication is mandatory for every account that can reach production, source code or customer data.
  • 4.9 Security is designed into Northwind rather than added afterwards: production changes follow the Change Management Policy, code is reviewed before merge in GitHub, and deployments run through GitHub Actions rather than from personal machines.
  • 4.10 Security incidents and suspected weaknesses are reported to security@northwindcloud.example as soon as they are noticed. Reporting in good faith never results in disciplinary action, even when the reporter caused the problem.
  • 4.11 Third parties that store or process company or customer data are assessed before onboarding and reviewed periodically under the Vendor and Third-Party Risk Management Policy.
  • 4.12 Northwind Cloud Inc states its security commitments externally through its terms of service, privacy notice, security page and customer contracts, and internally through this policy set, onboarding and training. Changes to external commitments are approved by Executive Management before publication.
  • 4.13 Deviations from any policy require a documented exception under section 6; undocumented deviations are policy violations. Compliance is verified through internal control reviews, the evidence collection in section 5, and the independent SOC 2 examination performed by a licensed CPA firm.

5. Procedures

  • 5.1 Annual objectives. In the first quarter of each fiscal year the Security Owner proposes security objectives, a control roadmap and a budget to Executive Management. Approved objectives are recorded in the security program plan and progress is reported quarterly.
  • 5.2 Policy lifecycle. The Security Owner maintains the policy register listing each policy, its owner, version, approval date and next review date. Revisions are approved by Priya Natarajan, CEO, versioned and communicated to affected personnel within ten business days.
  • 5.3 Acknowledgement and training. People Operations collects acknowledgement from every new hire before access is granted and from all personnel at each annual review, assigns awareness training within thirty days of hire and annually thereafter, and reports outstanding items to the Security Owner monthly. Records are retained for seven years under the Data Retention and Disposal Policy.
  • 5.4 Management reporting. The Security Owner delivers a written status report to Executive Management at least quarterly covering open risks, incidents, vulnerability and patch status, access review results, vendor reviews and progress against objectives. Decisions are minuted.
  • 5.5 Control evidence. The Security Owner maintains a control matrix mapping each criterion in scope (Security and Availability) to the policy statements and evidence artifacts that satisfy it. Evidence is collected on the cadence in the matrix and stored where the CPA firm can be given read access.
  • 5.6 Exceptions. Requests are submitted in writing to the Security Owner stating the statement affected, the justification, compensating controls, the risk owner and an expiry date no more than twelve months out. Approved exceptions are logged in the exception register and reviewed at each annual review.
  • 5.7 Incident escalation. Anyone who suspects an incident reports it to security@northwindcloud.example. The Security Owner triages within one business day under the Incident Response Policy and informs Executive Management of any incident affecting customer data or the availability of Northwind.
  • 5.8 Independent examination. The Security Owner coordinates scoping, evidence requests, walkthroughs and remediation with the CPA firm. Findings are tracked to closure in the risk register with an owner and due date.

6. Exceptions

Exceptions to this or any supporting policy are granted only in writing by the Security Owner, and additionally by Priya Natarajan, CEO where customer data is affected. Each exception records the requirement waived, the business reason, compensating controls, the risk owner and an expiry date. Exceptions expire automatically and are re-justified rather than renewed by default; the register is available to the CPA firm on request.

7. Enforcement

Violations are handled by People Operations with the Security Owner and may result in retraining, loss of access, disciplinary action up to and including termination of employment or contract, and, where the law requires, referral to authorities. Enforcement is proportionate: honest mistakes reported promptly are treated differently from deliberate or repeated violations.

8. Review Cadence

The Security Owner reviews this policy at the annual policy review, after any significant security incident, after material changes to the business, infrastructure or regulatory obligations of Northwind Cloud Inc, and after each SOC 2 examination. Each review is recorded in section 9 even where nothing changes; revisions are approved by Priya Natarajan, CEO before they take effect.

9. Revision History

VersionDateDescriptionApproved by
1.02026-09-02Initial releasePriya Natarajan, CEO

Frequently asked questions

Who should own the Information Security Policy?
In the Policyseed template the Security Owner owns the Information Security Policy: they maintain the text, run the procedures in section 5 and hold the evidence those procedures produce. The approver you name in the intake signs it, and section 8 sets the review cadence you choose (annual, semi-annual or quarterly).
Which SOC 2 criteria does the Information Security Policy address?
10 criteria in the Policyseed crosswalk: CC1.1 (Integrity and ethical values), CC1.2 (Oversight by leadership), CC1.3 (Structure, reporting lines and authority), CC1.5 (Accountability), CC2.2 (Internal communication), CC3.1 (Objectives for risk assessment), CC4.1 (Ongoing and separate evaluations), CC4.2 (Communicating deficiencies), CC5.1 (Selecting control activities) and CC5.3 (Policies and procedures). Each mapping points at a numbered section of this policy, and the Audit Kit exports the same mapping as an Excel crosswalk with an evidence checklist.
Is the Information Security Policy template free to use?
Yes. The template is Apache-2.0 licensed and the generator renders it in your browser with your company, stack and owner names filled in; nothing is stored server-side. The Audit Kit ($39 one-time) rewrites sections 4 and 5 for your named tools with Claude and adds Word documents, the crosswalk spreadsheet, acknowledgment forms and a review calendar. Refunds are available within 14 days on request. Policyseed provides governance policy templates, not legal advice; the CPA firm performs the examination.

Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.