An information security policy (ISP), also called a written information security policy or WISP, is the master document that consolidates all of an organization's security policies into a single governing framework. Many states and regulated industries now require businesses to maintain one.
Information Security Policy (ISP)
If you've ever watched the Lord of the Rings series, they have the one ring that rules them all. That's kind of like what an information security policy is, an ISP.
An ISP, or information security policy, is kind of the overall umbrella of our policies. An information security policy is just your security policies in writing. In fact, some people call this a written information security policy, or a WISP, instead of just an information security policy.
And this is a requirement for many businesses. In fact, many states — and it's a growing number of states — are requiring you to have a WISP, and there are certain industries that have had this requirement for a while. So this might be something that your business needs to have.
Now the thing is, an information security policy is just all your policies that are written down in a document. But if you're a larger business, you probably have many policies. So you might have a disaster recovery policy, an SDLC policy, a risk management policy — you might have all of these policies. So in that case I like to think of the information security policy as more like a book. It is a book with many chapters, and the chapters of this book are all of the other governing policies, these high-level policies that are all wrapped up into this book.
I did a search for some examples of a written information security policy, just so you have a visual of what these look like. They can vary a lot in what they look like and how they're formed, and it depends on the industry that you're in. Some industries, it's just a requirement; depending on what state you're in, there's a requirement.
So I looked this one up. This is one that's a very basic one for lawyers, clearinghouse.gov, that they have. So this is just one example right here, and in fact if we scroll to the bottom, it actually has a signature line on it, so people need to acknowledge this.
And then I have one right here from a university. So if we scroll through here, here's a very different format that they have right here. So that's not one size fits all — they're very different out there.
But essentially it's all of the security policies that are written out and on some sort of form, whether it's advertised out there or it's some sort of internal document. But it sets the tone for how the security department is going to operate.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →