Policies approval process
Assign topic to the user
Answer: First of all, to be sure about which policies the Governance board should approve you need to verify the current set of roles and responsibilities defined to it (e.g., the documented top management decision that established the Governance board). In general, policies can be divided in two types:
- High level policies, which define the organization's approach to broad issues, like quality policy, information security policy and IT security policy.
- Support policies, which define the organization's approach to specific issues, normally related to a high level policy like development polic y, information classification policy and access control policy.
Normally, a Governance board is responsible to approve high level policies, delegating the approval of support policies to specific roles in the organization, such as the HR department head or the IT senior manager.
Regarding how to name the policies, the word "standard" has a general understanding that is different from the purpose of a policy, then you should avoid use it to designate a policy not to cause confusion. A better approach would be to use the word "policy" to refer to high level policies approved by the Governance board and terms like "support policy", "detailed policy" or "complementary policy" to indicate policies that are related to a high level policy.
These articles will provide you further explanation about policies development:
- One Information Security Policy, or several policies? https://advisera.com/27001academy/blog/2013/06/18/one-information-security-policy-or-several-policies/
- 8 criteria to decide which ISO 27001 policies and procedures to write https://advisera.com/27001academy/blog/2014/07/28/8-criteria-to-decide-which-iso-27001-policies-and-procedures-to-write/
This material will also help you regarding policies development:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
Comment as guest or Sign in
Dec 19, 2017