Information Security Policy

Company policy

An information security policy an auditor can follow and a staff member can actually obey, including what happens when someone makes a mistake.

Make one like thisEditable, then download as a PDF

The whole document

Every page as it was built, in order. All the wording, figures and tables were written for this example, so the structure can be judged on real content.

This policy sets out how Cordell Wealth Advisers protects client and company information. It exists because we hold financial records for 2,400 clients, and a breach would harm those clients and end our licence.

This policy applies to every employee, contractor, volunteer and board member, on any device used for company work, including personal phones and home computers. It covers information in any form: systems, email, paper, and conversations.

Every system uses a unique password of at least 14 characters, stored in the company password manager. Multi factor authentication is on for email, the client system, and any remote access. Never share an account, not even with your manager.
Company laptops are encrypted and locked when you step away. Personal devices used for work must have a screen lock, an up to date operating system, and the ability to be wiped remotely if lost.
Client documents live in the client system, never on a desktop, a personal drive or a USB stick. Email attachments containing client data must be sent through the secure portal, not as plain attachments.
Do not discuss client matters in public. Use a privacy screen on public transport. Public wifi is fine for browsing but the company VPN must be on before you open any system.
Only install software from the approved list. If you need a tool that is not on it, ask; the answer is often yes, and shadow tools are how data leaves without anyone noticing.

Everyone completes security training within two weeks of starting, and a 30 minute refresher each year. Phishing simulations run quarterly; failing one means a short retraining session, not a disciplinary process.

Deliberate breaches, such as sharing an account or moving client data to a personal drive, are treated as misconduct and may lead to dismissal. Honest mistakes reported quickly are treated as learning, and that difference is deliberate.

The Head of Risk reviews this policy every 12 months, or sooner after a significant incident or a change in law. Version 4.0 replaces version 3.2 of September 2025. The change log is held with the policy register.

What makes this document work

Reporting is made safe

One hour to report, and a line saying you will not be punished for reporting honestly, which is what actually gets incidents reported.

Responsibilities are a table

Board, risk, managers, everyone, and the IT provider. No one can claim it was someone else.

It separates mistakes from misconduct

Sharing an account is misconduct, an honest error reported quickly is training. Stated on purpose.

Questions people ask

What sections does a policy need?

Purpose, scope, the rules, responsibilities, what happens on a breach, and when it is reviewed.

How long should a policy be?

Short enough to be read. Two to four pages beats twenty that nobody opens.

Who approves a policy?

Usually the board or executive, with a named owner who maintains it. Both are on the cover of this example.

How often should it be reviewed?

Every twelve months, and straight after a significant incident or a change in law.

Make yours in about a minute

The button opens the document generator with this document already described. Change the wording to your own business, pick a theme, and edit any section afterwards.

Make my company policy

Other document examples

New to the builder? Start withcreate a document with AI, thenlay it out exactly how you want it.