Expert TipPolicies & Documentation

Writing Policies That Actually Get Read

How to write ISO 27001 policies that are practical, compliant, and don't collect dust in a shared drive.

Updated 8 Mar 2026

The Problem With Most Policies

Most ISO 27001 policies fail not because they're technically wrong, but because nobody reads them. A 40-page Information Security Policy that nobody follows is worse than useless — it creates a false sense of security.

What Makes a Good Policy

Keep It Short

Aim for 2–5 pages maximum. If you need more detail, create supporting procedures.

Use Plain Language

Write for your audience, not for the auditor. If a developer can't understand your access control policy, it won't be followed.

Be Specific Enough to Act On

"Passwords must be strong" is useless. "Passwords must be at least 12 characters with mixed case and numbers" is actionable.

Include the Why

People follow rules they understand. Briefly explain the risk each policy addresses.

Structure That Works

1Purpose — one paragraph
2Scope — who does this apply to?
3Policy statements — clear, numbered requirements
4Responsibilities — who does what?
5Review — when and by whom?

Auditor View

Auditors don't want to read War and Peace either. They check:

Are policies approved by management?
Are they communicated to relevant personnel?
Are they reviewed at planned intervals?
Do people actually know what's in them?

Related Modules

Documents
Standard Controls

Related Controls / Clauses

5.1
5.2
A.5.1

26 practitioner guides — included free with your workspace

27 Launchpad generates your full compliance toolkit from a 10-minute setup: policies, risk register, legal register, controls, and AI-assisted document review.