What it has to decide
- A named accountable owner, by role
Not a committee and not a department. One role that carries the consequence if the program fails. Committees advise; they do not carry accountability, and an auditor will ask who does.
- Stated risk appetite, in terms you could test
"We take security seriously" is not an appetite. An appetite says what the organisation will accept: which systems may run with a known high finding, for how long, and who is permitted to accept that.
- The authority this policy grants
Say explicitly that subordinate policies and standards are issued under this one, and that they are binding. Without this sentence, every downstream policy has to argue for its own authority.
- Scope, including what is deliberately out
Name the entities, systems and locations covered, and name the exclusions. Unstated exclusions are read as omissions, and an exclusion you cannot justify is a finding.
- The exception route
There will be exceptions. Say who may grant one, for how long, on what evidence, and where the register lives. Policies with no exception route do not get followed, they get quietly ignored.
- Approval and review
Who approved it, on what date, and how often it is reviewed. This is the single most commonly failed clause in the whole document, because it is the easiest one to check.
How it is usually got wrong
- The policy states an annual review and the approval date is two or three years old. This is the most frequently raised finding in information security audits, and it is entirely self-inflicted.
- Risk appetite is described in adjectives rather than thresholds, so no decision can ever be tested against it.
- Accountability is assigned to a committee, which means it is assigned to nobody.
- The policy is approved by the security function rather than by the body that can actually fund it.
- It runs to forty pages, which guarantees that the people it binds have not read it.
Worked extract
What a decision looks like once it has been madeThe Board delegates accountability for information security to the Chief Information Security Officer. The organisation accepts residual risk rated Medium or below without further approval. Residual risk rated High may be accepted only by the Executive Risk Committee, for a defined period not exceeding six months, recorded in the Risk Register with a named owner and a remediation date. Residual risk rated Critical may not be accepted. Any system operating with an unremediated Critical finding must be withdrawn from service or compensating controls must be approved by the Committee before the next business day.