An overarching information security policy and a set of topic-specific policies are to be written, signed off by management, made available, brought to the attention of the staff and outside parties they concern, confirmed as received by those people, and revisited on a schedule and whenever something significant changes. Purpose: keep management's direction on information security fit, sufficient and working, in line with business, legal, regulatory and contractual needs. Guidance: top management approves the top-level policy, which states how the organization runs information security and draws on business strategy, laws and contracts, and present and expected risks and threats. It should cover what information security means for the organization, its objectives or how they are set, guiding principles, a commitment to meet applicable requirements and to keep improving the ISMS, which roles hold which responsibilities, and how exemptions and exceptions are handled; top management signs off any change to it. Beneath it sit topic-specific policies aimed at particular audiences or areas (for example access control, physical security, assets, information transfer, endpoint configuration, networks, incident management, backup, cryptography and keys, classification, technical vulnerabilities and secure development), consistent with the top policy and owned by people with the right authority and expertise. Reviews look for improvement and respond to shifts in strategy, technology, law and contracts, risks, the threat landscape and incident lessons, using management review and audit results, and check related policies for consistency. Policies should be understandable to their readers, acknowledged where appropriate, and screened for confidential content before being shared externally. The top policy is general and approved by top management; topic policies are detailed and approved at a suitable management level.
This control maps to 157 controls across 42 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
ISO 27002:2022 5.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.
The graph holds this control, the 157 it maps to, and the evidence behind each claim, over MCP and REST.