Policy
Information Security Policy
Arcfield shall protect the confidentiality, integrity and availability of information assets through a risk-based Information Security Management System aligned with ISO/IEC 27001:2022. This policy applies to all personnel, contractors, systems, services, suppliers and processes within the approved ISMS scope. Top Management commits to providing resources, assigning responsibilities, supporting continual improvement and ensuring that information security objectives remain aligned with business, customer, legal, regulatory and contractual requirements.
Use approved accounts, systems and storage locations for company information. Apply least privilege and MFA for privileged, remote and customer-data access. Classify and handle information according to approved classification rules. Report suspected incidents, weaknesses, data exposure or lost devices without delay. Assess security risk before significant supplier, system, architecture or processing changes. Keep security evidence complete, current and retrievable. Manage exceptions through documented approval, compensating controls and expiry. Review policies, risks and controls after major changes or incidents. Exceptions require documented justification, risk assessment, owner approval, expiry date and compensating controls. New personnel and contractors acknowledge this policy before access to Confidential or Restricted information. Overdue acknowledgements are escalated and tracked to closure.
Supporting topic policies must be checkable against this file. This file does not duplicate ISS, RAM, RR or the SoA. Risk treatment decisions live in RAM, RR and the SoA. This policy requires those records to exist; it does not score residual risk. This file is a fictional Arcfield example, not your organization's approved policy. Copy this file as the controlled Word master for your ISMS only after you replace Arcfield decisions with your own.
