The Problem With Most Policies
Most ISO 27001 policies fail not because they're technically wrong, but because nobody reads them. A 40-page Information Security Policy that nobody follows is worse than useless — it creates a false sense of security.
What Makes a Good Policy
Keep It Short
Aim for 2–5 pages maximum. If you need more detail, create supporting procedures.
Use Plain Language
Write for your audience, not for the auditor. If a developer can't understand your access control policy, it won't be followed.
Be Specific Enough to Act On
"Passwords must be strong" is useless. "Passwords must be at least 12 characters with mixed case and numbers" is actionable.
Include the Why
People follow rules they understand. Briefly explain the risk each policy addresses.
Structure That Works
Auditor View
Auditors don't want to read War and Peace either. They check: