2. Policies and your responsibilities
The ISMS policy set
An ISMS is held together by a set of written policies. They are not paperwork for its own sake: each one translates the organisation's risk decisions into rules you can actually follow. You will meet these four constantly.
Acceptable use
The acceptable use policy sets out what you may and may not do with the organisation's systems, devices, and accounts. It typically covers things like personal use of work equipment, installing software, using work email and accounts for non-work purposes, and what is never acceptable, such as disabling security tools or sharing your credentials. If you are ever unsure whether something is allowed on a work device, this is the policy to check.
Access control
The access control policy governs who gets access to which systems and information, how that access is requested and approved, and how it is reviewed and removed. It is the policy behind the sometimes frustrating experience of having to raise a request for a system rather than just being given the password. That friction is deliberate.
Information classification and handling
This policy defines the sensitivity levels the organisation uses, for example Public, Internal, and Confidential, and the handling rules attached to each: who may see it, where it may be stored, whether it can be emailed externally, and how it must be disposed of. The label on a document is an instruction, not a decoration.
Clear desk and clear screen
A simple pair of habits with an outsized effect. Clear desk means sensitive papers, removable media, and notes are locked away when you leave your workspace, not left out overnight or in meeting rooms. Clear screen means you lock your computer whenever you step away, even for a minute, so nobody can read or act from your screen. In shared offices, at home, and especially in public spaces, these two habits close off some of the easiest attacks there are.
Take ten minutes to find where these policies live in your organisation. Knowing where to look is half the job.
› Course contents
What ISO 27001 is
Policies and your responsibilities
Everyday controls
Incidents, audits and improvement