TechKnowSurge
NIST 800-53 PM-1 NIST CSF GV.PO-01 ISC2 CISSP 1.6 CompTIA Security+ 5.1
VideoSecurityFree

Information Security Policy (ISP)

An information security policy (ISP), also called a written information security policy or WISP, is the master document that consolidates all of an organization's security policies into a single governing framework. Many states and regulated industries now require businesses to maintain one.

Complete this video to capture a CTF flag worth 1 point.

About this video

An information security policy (ISP), also referred to as a written information security policy or WISP, is the master governing document that consolidates all of an organization's security policies into a single, unified framework. It defines in writing how the security function operates and sets the standard against which all other security decisions and procedures are measured. For smaller organizations, the WISP may be a concise standalone document, but for larger enterprises it functions more like a book — one whose individual chapters represent separate high-level policies covering areas such as disaster recovery, risk management, and the software development lifecycle. WISP formats vary considerably across industries and organizations. Some are brief, straightforward documents requiring staff acknowledgment and signature, while others are extensive policy sets structured around regulatory or institutional requirements. There is no universal template, and what an organization's WISP looks like depends largely on its size, sector, and applicable compliance obligations. Regardless of format, the document's role remains consistent: to articulate security expectations and provide a documented foundation for the entire security program. Compliance pressure around WISPs is increasing. A growing number of U.S. states now mandate that businesses maintain a written information security policy, and several regulated industries — such as healthcare, finance, and legal services — have carried this requirement for years. Organizations operating in these spaces should treat the WISP not as an optional best practice but as a baseline compliance requirement.

What you'll learn

What's covered

Information Security Policy (ISP)

Aligned to

NIST 800-53
PM-1 Information Security Program Plan
NIST CSF
GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced.
ISC2 CISSP
1.6 Develop, document, and implement security policy, standards, procedures, and guidelines
CompTIA Security+
5.1 Summarize elements of effective security governance.

Key terms

Information Security Policy
ISP
A governing document that consolidates an organization's security policies into a single overarching framework, setting the tone for how security operations are conducted.
Written Information Security Policy
WISP
An Information Security Policy that is formally documented in writing, often required by law or industry regulation.
Security Policy
A formal document that defines an organization's security goals, rules, and responsibilities.
Risk Management
The ongoing process of identifying, assessing, and mitigating risks to an acceptable level.
Disaster Recovery
DR
The process and procedures for recovering IT systems and data following a disruptive event.

Topics

Information Security Policy Wisp Security Governance Policy Framework Regulatory Compliance Cybersecurity

Transcript

If you've ever watched the Lord of the Rings series, they have the one ring that rules them all. That's kind of like what an information security policy is, an ISP.

An ISP, or information security policy, is kind of the overall umbrella of our policies. An information security policy is just your security policies in writing. In fact, some people call this a written information security policy, or a WISP, instead of just an information security policy.

And this is a requirement for many businesses. In fact, many states — and it's a growing number of states — are requiring you to have a WISP, and there are certain industries that have had this requirement for a while. So this might be something that your business needs to have.

Now the thing is, an information security policy is just all your policies that are written down in a document. But if you're a larger business, you probably have many policies. So you might have a disaster recovery policy, an SDLC policy, a risk management policy — you might have all of these policies. So in that case I like to think of the information security policy as more like a book. It is a book with many chapters, and the chapters of this book are all of the other governing policies, these high-level policies that are all wrapped up into this book.

Examples

I did a search for some examples of a written information security policy, just so you have a visual of what these look like. They can vary a lot in what they look like and how they're formed, and it depends on the industry that you're in. Some industries, it's just a requirement; depending on what state you're in, there's a requirement.

So I looked this one up. This is one that's a very basic one for lawyers, clearinghouse.gov, that they have. So this is just one example right here, and in fact if we scroll to the bottom, it actually has a signature line on it, so people need to acknowledge this.

And then I have one right here from a university. So if we scroll through here, here's a very different format that they have right here. So that's not one size fits all — they're very different out there.

But essentially it's all of the security policies that are written out and on some sort of form, whether it's advertised out there or it's some sort of internal document. But it sets the tone for how the security department is going to operate.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →