Information security policies communicate management direction, responsibilities and expected behaviour. This section distinguishes program, issue-specific and system-specific policies.

Choose the level of detail that the audience and subject need. Keep policies connected to the procedures, controls and evidence used to apply them, and review them when organisational objectives, obligations or risks change.