ISO 27001

What policies are required for ISO 27001?

ISO 27001 requires a top-level information security policy, plus supporting policies driven by your risk assessment and Statement of Applicability, commonly covering access control, acceptable use, cryptography, supplier/vendor security, incident management, business continuity, secure development, HR security, and data classification and handling.

One required policy, many supporting ones

ISO 27001 explicitly requires a top-level information security policy approved by leadership. Beyond that, the policies you need are the ones your risk assessment and Statement of Applicability say apply, not a fixed checklist.

Commonly needed policies

Access control; acceptable use; cryptography/encryption; supplier and vendor security; incident management; business continuity; secure development; human-resource security (screening, onboarding, offboarding); and data classification and handling.

Keep policies tied to controls

Policies are only useful if they map to real controls and evidence. Keel provides framework-mapped policy templates and an AI drafter, so each policy links to the controls it supports and the evidence that proves it operates.

FAQ

Is there a fixed list of ISO 27001 policies?

No. Only the top-level information security policy is explicitly required. The rest follow from your risk assessment and Statement of Applicability, so two organizations can legitimately have different policy sets.

Can I reuse SOC 2 policies for ISO 27001?

Largely yes. The underlying controls overlap heavily, so well-written policies can support both with minor adjustments.

Related

What is ISO 27001? → Policy management in Keel → How long does ISO 27001 take? →

Get audit-ready with Keel

The AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.

Start free