Free Security Policy Templates and Examples
Security, privacy and governance policies that hold up with auditors and customers. Generate a template tailored to your company, free, or read worked examples for a seed-stage startup, a fintech, a healthcare SaaS and more.
9 of 70 templates ready, with 55 worked examples. More are added in batches.
Showing all 70 documents
No documents match your search
Try a shorter term or an abbreviation, or clear the filters to see the whole library.
Security governance and people
2 of 7 ready
The top-level rules for security, who owns them, and what staff are expected to do.
Information Security Policy
The top-level policy that sets your security objectives, who is responsible for them and the rules every other policy builds on. It is the first document auditors and customers ask for.
- SOC 2
- ISO 27001
- HIPAA
Acceptable Use Policy
Sets out how staff may use company devices, accounts, email, the internet and AI tools, and what the company monitors. Security questionnaires often ask whether you have one and whether staff have acknowledged it.
- SOC 2
- ISO 27001
Information Security Roles and Responsibilities
Names who owns security decisions, risks and controls, from the board to individual staff. Useful when auditors ask who is accountable for each area.
- SOC 2
- ISO 27001
Security Awareness and Training Policy
Defines the security training staff receive when they join and each year after, including phishing tests. Auditors check training records against it.
- SOC 2
- ISO 27001
- HIPAA
Personnel Screening Policy
Covers the background checks you run before hiring, scaled to the role and local law. Customers with sensitive data often ask about it.
- SOC 2
- ISO 27001
Information Classification Policy
Sorts your information into levels such as public, internal and confidential, with handling rules for each. Other policies refer to these levels.
- SOC 2
- ISO 27001
Asset Management Policy
Explains how you keep an inventory of devices, systems and data, who owns each asset, and how assets are returned when people leave.
- SOC 2
- ISO 27001
Access and identity
1 of 4 ready
Who can get into which systems, how access is granted, and how it is taken away.
Access Control Policy
Sets the rules for who can use which systems and data, and how access is approved, reviewed and removed. Auditors test it against your real user accounts.
- SOC 2
- ISO 27001
- HIPAA
Privileged Access Management Policy
Covers admin and root accounts: who gets them, how they are protected and how their use is logged. Attackers target these accounts first.
- SOC 2
- ISO 27001
Password Management Policy
Sets rules for passwords, password managers and multi-factor authentication, in line with current NIST guidance rather than forced monthly changes.
- SOC 2
- ISO 27001
- HIPAA
Joiners, Movers and Leavers Procedure
The steps for giving new starters access, changing it when people move roles, and removing it on their last day. Auditors sample leavers to check it happened.
- SOC 2
- ISO 27001
Operations security
Coming soon
The day-to-day technical controls that keep systems patched, monitored, encrypted and backed up.
Encryption and Key Management Policy
Says what data must be encrypted at rest and in transit, which algorithms to use, and how keys are created, stored and rotated.
- SOC 2
- ISO 27001
- GDPR
- HIPAA
Backup Policy and Procedure
Sets what is backed up, how often, where copies are kept and how restores are tested. Customers ask for your backup frequency and last restore test.
- SOC 2
- ISO 27001
- HIPAA
Event Logging and System Monitoring Policy
Defines which events are logged, how long logs are kept, who reviews them and which alerts need a response.
- SOC 2
- ISO 27001
- HIPAA
Vulnerability and Patch Management Policy
Sets how you find vulnerabilities, how quickly each severity must be fixed and how exceptions are approved.
- SOC 2
- ISO 27001
Penetration Testing Policy
Covers how often you commission penetration tests, what is in scope and how findings are fixed. Enterprise customers often ask for the latest summary.
- SOC 2
- ISO 27001
Secure Configuration and Hardening Policy
Sets the baseline settings for servers, laptops and cloud services, such as CIS Benchmarks, and how drift from them is caught.
- SOC 2
- ISO 27001
Anti-Malware Policy
Covers endpoint protection on company devices and servers, how it is kept up to date and what happens when it finds something.
- SOC 2
- ISO 27001
- HIPAA
Network Security Policy
Sets rules for firewalls, network segmentation, Wi-Fi and cloud security groups, and how changes to them are approved.
- SOC 2
- ISO 27001
Cloud Services Policy
Explains how cloud services are chosen, approved, configured and exited, and which security responsibilities stay with you rather than the provider.
- SOC 2
- ISO 27001
Threat Intelligence Policy
Sets how you collect information about threats relevant to your business and turn it into action. ISO 27001 added this control in 2022.
- ISO 27001
Information Transfer Policy
Covers how information is shared safely by email, file sharing and removable media, both inside the company and with third parties.
- ISO 27001
Vulnerability Disclosure Policy
A public statement telling security researchers how to report a vulnerability to you and what you will do with the report.
Coming soonDevelopment and suppliers
Coming soon
How software is built and changed safely, and how you manage the vendors you depend on.
Change Management Policy
Sets how changes to production systems are requested, reviewed, tested, approved and rolled back. SOC 2 auditors sample changes against it.
- SOC 2
- ISO 27001
Secure Development Lifecycle Policy
Builds security into how you design, code, test and release software, from threat modelling to dependency scanning.
- SOC 2
- ISO 27001
Open Source Software Policy
Sets which open source licences you can use, how dependencies are approved and tracked, and how you respond to vulnerable packages.
Coming soonSupplier Management Policy
Explains how you assess vendors before signing, what security terms you require and how often you review them.
- SOC 2
- ISO 27001
Physical and remote working
Coming soon
Offices, laptops, phones and home working, and what happens to equipment at the end of its life.
Physical Security Policy
Covers office access, visitors and equipment protection. For fully remote companies it explains how this is handled by your cloud providers instead.
- SOC 2
- ISO 27001
- HIPAA
Clear Desk and Clear Screen Policy
Asks staff to lock screens and put away sensitive papers when they step away, in the office and at home.
- ISO 27001
Remote Access Policy
Sets how staff and contractors connect to company systems from outside the office, including VPN or zero trust access and home networks.
- SOC 2
- ISO 27001
Mobile Device Policy (BYOD)
Covers phones, tablets and personal devices used for work: what is allowed, how they are managed and what happens if one is lost.
- SOC 2
- ISO 27001
Secure Disposal and Media Destruction Policy
Sets how laptops, drives and paper records are wiped or destroyed so data cannot be recovered, and what proof you keep.
- SOC 2
- ISO 27001
- HIPAA
Incident response and continuity
2 of 3 ready
What you do when something goes wrong, and how the business keeps running.
Incident Response Plan
The steps your team follows to detect, contain and recover from a security incident, with roles, severity levels and who to notify.
- SOC 2
- ISO 27001
- GDPR
- HIPAA
Disaster Recovery & Business Continuity Plan
How you keep critical services running through an outage or disaster and restore them within agreed recovery time and recovery point objectives.
- SOC 2
- ISO 27001
- HIPAA
Business Impact Analysis
Works out which processes and systems matter most, what an outage would cost and how quickly each must recover. It sets the targets your recovery plan has to meet.
- SOC 2
ISMS documents
1 of 10 ready
The management system documents ISO 27001 requires, from scope and risk to audit and review.
Risk Register
Records each information security and compliance risk with its score, owner, treatment and actions, and says how often each is reviewed.
- SOC 2
- ISO 27001
- HIPAA
ISMS Scope Statement
Defines which parts of the business, locations and systems your information security management system covers. It is the first mandatory ISO 27001 document.
- ISO 27001
Statement of Applicability
Lists every Annex A control, whether it applies to you, why, and whether it is in place. Certification auditors work from it.
- ISO 27001
- ISO 42001
Risk Management Policy
Sets your approach to risk: who owns it, how much risk the business will accept and how often risks are reviewed.
- SOC 2
- ISO 27001
Risk Assessment and Treatment Methodology
The method for identifying, scoring and treating risks, so every assessment gives consistent results. ISO 27001 requires it written down.
- SOC 2
- ISO 27001
- HIPAA
Legal, Regulatory and Contractual Requirements Register
Lists the laws, regulations and contract terms that affect your security and privacy, and who is responsible for meeting each.
- ISO 27001
Document Control Procedure
Sets how policies and records are written, approved, versioned, published and retired, so everyone works from the current version.
- ISO 27001
- ISO 42001
Internal Audit Procedure
Explains how you plan and run internal audits of your management system, who can carry them out and how findings are reported.
- ISO 27001
- ISO 42001
Management Review Procedure
Sets how leadership reviews the management system at planned intervals, what goes on the agenda and what decisions are recorded.
- ISO 27001
- ISO 42001
Nonconformity and Corrective Action Procedure
Explains how problems found by audits, incidents or staff are logged, investigated to their root cause and fixed for good.
- ISO 27001
- ISO 42001
Artificial intelligence
1 of 5 ready
Rules for using and building AI, and the records ISO 42001 and the EU AI Act expect.
Responsible AI Policy
The principles for building and using AI fairly and transparently, with human oversight and clear accountability when things go wrong.
- ISO 42001
- EU AI Act
AI Acceptable Use Policy
Tells staff which AI tools they may use, what data they can put into them and how to check the output before relying on it.
- ISO 42001
- EU AI Act
AI Governance Policy
Sets the management system around AI: who approves new AI uses, how they are assessed and how the company meets ISO 42001.
- ISO 42001
- EU AI Act
AI System Inventory
A list of every AI system you build or use, what it does, who owns it and its risk level. You need it before you can govern AI at all.
- ISO 42001
- EU AI Act
AI Risk Register
Records the risks from each AI system, such as bias, errors and data leakage, with owners and treatments.
- ISO 42001
- EU AI Act
Data protection
2 of 12 ready
Privacy documents for GDPR and similar laws, including the ones your customers will sign.
DPIA Procedure
Explains when a Data Protection Impact Assessment is needed and how to carry one out, with a template for recording it.
- GDPR
Data Management Policy
Sets how data is owned, stored, kept accurate, retained and deleted across its life, so it stays secure, reliable and compliant.
- SOC 2
- ISO 27001
- GDPR
Data Protection Policy
Sets how the company handles personal data lawfully, who is responsible and how staff should apply the data protection principles day to day.
- GDPR
- ISO 27001
Privacy Notice
The public notice on your website telling people what personal data you collect, why, who you share it with and what their rights are.
- GDPR
Website Cookies Policy
Explains which cookies and trackers your website uses, what they do and how visitors can control them.
- GDPR
Records of Processing Activities
The GDPR Article 30 record of what personal data you process, why, where it goes and how long you keep it.
- GDPR
Data Retention Schedule
Lists each type of record you hold, how long you keep it and why, and how it is deleted at the end.
- GDPR
- SOC 2
Data Subject Rights Procedure
The steps for handling requests from people to see, correct, delete or move their personal data within the legal deadlines.
- GDPR
Data Breach Response Procedure
What to do when personal data is lost or exposed, including the 72-hour regulator deadline under GDPR and notifying affected people.
- GDPR
- HIPAA
International Data Transfers Policy
Sets how personal data can leave the UK or EU lawfully, using adequacy decisions, standard contractual clauses and transfer risk assessments.
- GDPR
Sub-processor List
The public list of vendors that process your customers’ personal data, what they do and where. Customers check it before signing a DPA.
- GDPR
Data Processing Agreement
The contract that sets how you process personal data on a customer’s behalf, as GDPR Article 28 requires. Every enterprise deal asks for one.
- GDPR
Governance and ethics
Coming soon
Company-wide conduct policies that procurement teams and larger customers check for.
Code of Conduct
Sets the standards of behaviour expected of everyone who works for the company, and how to raise concerns. SOC 2 auditors look for it.
- SOC 2
Anti-Bribery and Corruption Policy
Bans bribes and sets rules for gifts, hospitality and dealing with officials, in line with the UK Bribery Act and the US FCPA.
Coming soonAnti-Facilitation of Tax Evasion Policy
Shows you have reasonable procedures to stop staff or partners helping anyone evade tax, as the UK Criminal Finances Act 2017 expects.
Coming soonFraud Prevention Policy
Sets how the company prevents, detects and responds to fraud, including payment fraud and fake invoices.
Coming soonConflict of Interest Policy
Asks staff to declare outside interests that could affect their decisions at work, and explains how each one is managed.
Coming soonWhistleblowing Policy
Explains how staff can report wrongdoing safely, including anonymously, and how they are protected from retaliation.
Coming soonModern Slavery Statement
The annual statement on the steps you take to prevent slavery and human trafficking in your business and supply chains.
Coming soonSupplier Code of Conduct
Sets the ethical, environmental and security standards you expect from your suppliers.
Coming soonQuestions about the policy templates
Are the templates really free?
Yes. There is nothing to pay and no copyright restrictions, so you can edit and use the documents however you like. We ask for an email address so we can send you the finished document.
How are these templates different from a standard template?
A standard template gives everyone the same text with blanks to fill in. Ours are written from your answers about your company’s size, industry, systems, customers and regulations, so it describes how you actually work. You get an editable Word document and a PDF by email, usually within a few minutes.
Will these documents make us SOC 2 or ISO 27001 compliant?
Not on their own. Policies show auditors and customers what you have committed to, and audits then check that you follow them. The framework tags on each document show which audits commonly expect it, so you can see which ones you need.
Which policies should we write first?
Start with the Information Security Policy, then the Access Control Policy, Incident Response Plan and Disaster Recovery & Business Continuity Plan. Security questionnaires and SOC 2 and ISO 27001 auditors ask for these four more than any others.
Is this legal advice?
No. The documents are a strong first draft, not legal advice. Have someone qualified review them before you adopt them, especially customer-facing documents such as a privacy notice or data processing agreement.
When will the coming-soon documents be ready?
We are adding them in batches, starting with the documents people search for and customers ask for most: the Risk Register, Privacy Notice and DPIA Procedure come next.