Free Security Policy Templates and Examples

Security, privacy and governance policies that hold up with auditors and customers. Generate a template tailored to your company, free, or read worked examples for a seed-stage startup, a fintech, a healthcare SaaS and more.

9 of 70 templates ready, with 55 worked examples. More are added in batches.

Framework

Showing all 70 documents

Security governance and people

2 of 7 ready

The top-level rules for security, who owns them, and what staff are expected to do.

Policy

Information Security Policy

The top-level policy that sets your security objectives, who is responsible for them and the rules every other policy builds on. It is the first document auditors and customers ask for.

  • SOC 2
  • ISO 27001
  • HIPAA
Get the free template
Policy

Acceptable Use Policy

Sets out how staff may use company devices, accounts, email, the internet and AI tools, and what the company monitors. Security questionnaires often ask whether you have one and whether staff have acknowledged it.

  • SOC 2
  • ISO 27001
Get the free template
Policy

Information Security Roles and Responsibilities

Names who owns security decisions, risks and controls, from the board to individual staff. Useful when auditors ask who is accountable for each area.

  • SOC 2
  • ISO 27001
Coming soon
Policy

Security Awareness and Training Policy

Defines the security training staff receive when they join and each year after, including phishing tests. Auditors check training records against it.

  • SOC 2
  • ISO 27001
  • HIPAA
Coming soon
Policy

Personnel Screening Policy

Covers the background checks you run before hiring, scaled to the role and local law. Customers with sensitive data often ask about it.

  • SOC 2
  • ISO 27001
Coming soon
Policy

Information Classification Policy

Sorts your information into levels such as public, internal and confidential, with handling rules for each. Other policies refer to these levels.

  • SOC 2
  • ISO 27001
Coming soon
Policy

Asset Management Policy

Explains how you keep an inventory of devices, systems and data, who owns each asset, and how assets are returned when people leave.

  • SOC 2
  • ISO 27001
Coming soon

Access and identity

1 of 4 ready

Who can get into which systems, how access is granted, and how it is taken away.

Policy

Access Control Policy

Sets the rules for who can use which systems and data, and how access is approved, reviewed and removed. Auditors test it against your real user accounts.

  • SOC 2
  • ISO 27001
  • HIPAA
Get the free template
Policy

Privileged Access Management Policy

Covers admin and root accounts: who gets them, how they are protected and how their use is logged. Attackers target these accounts first.

  • SOC 2
  • ISO 27001
Coming soon
Policy

Password Management Policy

Sets rules for passwords, password managers and multi-factor authentication, in line with current NIST guidance rather than forced monthly changes.

  • SOC 2
  • ISO 27001
  • HIPAA
Coming soon
Procedure

Joiners, Movers and Leavers Procedure

The steps for giving new starters access, changing it when people move roles, and removing it on their last day. Auditors sample leavers to check it happened.

  • SOC 2
  • ISO 27001
Coming soon

Operations security

Coming soon

The day-to-day technical controls that keep systems patched, monitored, encrypted and backed up.

Policy

Encryption and Key Management Policy

Says what data must be encrypted at rest and in transit, which algorithms to use, and how keys are created, stored and rotated.

  • SOC 2
  • ISO 27001
  • GDPR
  • HIPAA
Coming soon
Procedure

Backup Policy and Procedure

Sets what is backed up, how often, where copies are kept and how restores are tested. Customers ask for your backup frequency and last restore test.

  • SOC 2
  • ISO 27001
  • HIPAA
Coming soon
Policy

Event Logging and System Monitoring Policy

Defines which events are logged, how long logs are kept, who reviews them and which alerts need a response.

  • SOC 2
  • ISO 27001
  • HIPAA
Coming soon
Policy

Vulnerability and Patch Management Policy

Sets how you find vulnerabilities, how quickly each severity must be fixed and how exceptions are approved.

  • SOC 2
  • ISO 27001
Coming soon
Policy

Penetration Testing Policy

Covers how often you commission penetration tests, what is in scope and how findings are fixed. Enterprise customers often ask for the latest summary.

  • SOC 2
  • ISO 27001
Coming soon
Policy

Secure Configuration and Hardening Policy

Sets the baseline settings for servers, laptops and cloud services, such as CIS Benchmarks, and how drift from them is caught.

  • SOC 2
  • ISO 27001
Coming soon
Policy

Anti-Malware Policy

Covers endpoint protection on company devices and servers, how it is kept up to date and what happens when it finds something.

  • SOC 2
  • ISO 27001
  • HIPAA
Coming soon
Policy

Network Security Policy

Sets rules for firewalls, network segmentation, Wi-Fi and cloud security groups, and how changes to them are approved.

  • SOC 2
  • ISO 27001
Coming soon
Policy

Cloud Services Policy

Explains how cloud services are chosen, approved, configured and exited, and which security responsibilities stay with you rather than the provider.

  • SOC 2
  • ISO 27001
Coming soon
Policy

Threat Intelligence Policy

Sets how you collect information about threats relevant to your business and turn it into action. ISO 27001 added this control in 2022.

  • ISO 27001
Coming soon
Policy

Information Transfer Policy

Covers how information is shared safely by email, file sharing and removable media, both inside the company and with third parties.

  • ISO 27001
Coming soon
Policy

Vulnerability Disclosure Policy

A public statement telling security researchers how to report a vulnerability to you and what you will do with the report.

Coming soon

Development and suppliers

Coming soon

How software is built and changed safely, and how you manage the vendors you depend on.

Policy

Change Management Policy

Sets how changes to production systems are requested, reviewed, tested, approved and rolled back. SOC 2 auditors sample changes against it.

  • SOC 2
  • ISO 27001
Coming soon
Policy

Secure Development Lifecycle Policy

Builds security into how you design, code, test and release software, from threat modelling to dependency scanning.

  • SOC 2
  • ISO 27001
Coming soon
Policy

Open Source Software Policy

Sets which open source licences you can use, how dependencies are approved and tracked, and how you respond to vulnerable packages.

Coming soon
Policy

Supplier Management Policy

Explains how you assess vendors before signing, what security terms you require and how often you review them.

  • SOC 2
  • ISO 27001
Coming soon

Physical and remote working

Coming soon

Offices, laptops, phones and home working, and what happens to equipment at the end of its life.

Policy

Physical Security Policy

Covers office access, visitors and equipment protection. For fully remote companies it explains how this is handled by your cloud providers instead.

  • SOC 2
  • ISO 27001
  • HIPAA
Coming soon
Policy

Clear Desk and Clear Screen Policy

Asks staff to lock screens and put away sensitive papers when they step away, in the office and at home.

  • ISO 27001
Coming soon
Policy

Remote Access Policy

Sets how staff and contractors connect to company systems from outside the office, including VPN or zero trust access and home networks.

  • SOC 2
  • ISO 27001
Coming soon
Policy

Mobile Device Policy (BYOD)

Covers phones, tablets and personal devices used for work: what is allowed, how they are managed and what happens if one is lost.

  • SOC 2
  • ISO 27001
Coming soon
Policy

Secure Disposal and Media Destruction Policy

Sets how laptops, drives and paper records are wiped or destroyed so data cannot be recovered, and what proof you keep.

  • SOC 2
  • ISO 27001
  • HIPAA
Coming soon

Incident response and continuity

2 of 3 ready

What you do when something goes wrong, and how the business keeps running.

ISMS documents

1 of 10 ready

The management system documents ISO 27001 requires, from scope and risk to audit and review.

Register

Risk Register

Records each information security and compliance risk with its score, owner, treatment and actions, and says how often each is reviewed.

  • SOC 2
  • ISO 27001
  • HIPAA
Get the free template
Statement

ISMS Scope Statement

Defines which parts of the business, locations and systems your information security management system covers. It is the first mandatory ISO 27001 document.

  • ISO 27001
Coming soon
Statement

Statement of Applicability

Lists every Annex A control, whether it applies to you, why, and whether it is in place. Certification auditors work from it.

  • ISO 27001
  • ISO 42001
Coming soon
Policy

Risk Management Policy

Sets your approach to risk: who owns it, how much risk the business will accept and how often risks are reviewed.

  • SOC 2
  • ISO 27001
Coming soon
Procedure

Risk Assessment and Treatment Methodology

The method for identifying, scoring and treating risks, so every assessment gives consistent results. ISO 27001 requires it written down.

  • SOC 2
  • ISO 27001
  • HIPAA
Coming soon
Register

Legal, Regulatory and Contractual Requirements Register

Lists the laws, regulations and contract terms that affect your security and privacy, and who is responsible for meeting each.

  • ISO 27001
Coming soon
Procedure

Document Control Procedure

Sets how policies and records are written, approved, versioned, published and retired, so everyone works from the current version.

  • ISO 27001
  • ISO 42001
Coming soon
Procedure

Internal Audit Procedure

Explains how you plan and run internal audits of your management system, who can carry them out and how findings are reported.

  • ISO 27001
  • ISO 42001
Coming soon
Procedure

Management Review Procedure

Sets how leadership reviews the management system at planned intervals, what goes on the agenda and what decisions are recorded.

  • ISO 27001
  • ISO 42001
Coming soon
Procedure

Nonconformity and Corrective Action Procedure

Explains how problems found by audits, incidents or staff are logged, investigated to their root cause and fixed for good.

  • ISO 27001
  • ISO 42001
Coming soon

Artificial intelligence

1 of 5 ready

Rules for using and building AI, and the records ISO 42001 and the EU AI Act expect.

Policy

Responsible AI Policy

The principles for building and using AI fairly and transparently, with human oversight and clear accountability when things go wrong.

  • ISO 42001
  • EU AI Act
Get the free template
Policy

AI Acceptable Use Policy

Tells staff which AI tools they may use, what data they can put into them and how to check the output before relying on it.

  • ISO 42001
  • EU AI Act
Coming soon
Policy

AI Governance Policy

Sets the management system around AI: who approves new AI uses, how they are assessed and how the company meets ISO 42001.

  • ISO 42001
  • EU AI Act
Coming soon
Register

AI System Inventory

A list of every AI system you build or use, what it does, who owns it and its risk level. You need it before you can govern AI at all.

  • ISO 42001
  • EU AI Act
Coming soon
Register

AI Risk Register

Records the risks from each AI system, such as bias, errors and data leakage, with owners and treatments.

  • ISO 42001
  • EU AI Act
Coming soon

Data protection

2 of 12 ready

Privacy documents for GDPR and similar laws, including the ones your customers will sign.

Procedure

DPIA Procedure

Explains when a Data Protection Impact Assessment is needed and how to carry one out, with a template for recording it.

  • GDPR
Get the free template
Policy

Data Management Policy

Sets how data is owned, stored, kept accurate, retained and deleted across its life, so it stays secure, reliable and compliant.

  • SOC 2
  • ISO 27001
  • GDPR
Get the free template
Policy

Data Protection Policy

Sets how the company handles personal data lawfully, who is responsible and how staff should apply the data protection principles day to day.

  • GDPR
  • ISO 27001
Coming soon
Notice

Privacy Notice

The public notice on your website telling people what personal data you collect, why, who you share it with and what their rights are.

  • GDPR
Coming soon
Notice

Website Cookies Policy

Explains which cookies and trackers your website uses, what they do and how visitors can control them.

  • GDPR
Coming soon
Register

Records of Processing Activities

The GDPR Article 30 record of what personal data you process, why, where it goes and how long you keep it.

  • GDPR
Coming soon
Register

Data Retention Schedule

Lists each type of record you hold, how long you keep it and why, and how it is deleted at the end.

  • GDPR
  • SOC 2
Coming soon
Procedure

Data Subject Rights Procedure

The steps for handling requests from people to see, correct, delete or move their personal data within the legal deadlines.

  • GDPR
Coming soon
Procedure

Data Breach Response Procedure

What to do when personal data is lost or exposed, including the 72-hour regulator deadline under GDPR and notifying affected people.

  • GDPR
  • HIPAA
Coming soon
Policy

International Data Transfers Policy

Sets how personal data can leave the UK or EU lawfully, using adequacy decisions, standard contractual clauses and transfer risk assessments.

  • GDPR
Coming soon
Register

Sub-processor List

The public list of vendors that process your customers’ personal data, what they do and where. Customers check it before signing a DPA.

  • GDPR
Coming soon
Agreement

Data Processing Agreement

The contract that sets how you process personal data on a customer’s behalf, as GDPR Article 28 requires. Every enterprise deal asks for one.

  • GDPR
Coming soon

Governance and ethics

Coming soon

Company-wide conduct policies that procurement teams and larger customers check for.

Policy

Code of Conduct

Sets the standards of behaviour expected of everyone who works for the company, and how to raise concerns. SOC 2 auditors look for it.

  • SOC 2
Coming soon
Policy

Anti-Bribery and Corruption Policy

Bans bribes and sets rules for gifts, hospitality and dealing with officials, in line with the UK Bribery Act and the US FCPA.

Coming soon
Policy

Anti-Facilitation of Tax Evasion Policy

Shows you have reasonable procedures to stop staff or partners helping anyone evade tax, as the UK Criminal Finances Act 2017 expects.

Coming soon
Policy

Fraud Prevention Policy

Sets how the company prevents, detects and responds to fraud, including payment fraud and fake invoices.

Coming soon
Policy

Conflict of Interest Policy

Asks staff to declare outside interests that could affect their decisions at work, and explains how each one is managed.

Coming soon
Policy

Whistleblowing Policy

Explains how staff can report wrongdoing safely, including anonymously, and how they are protected from retaliation.

Coming soon
Statement

Modern Slavery Statement

The annual statement on the steps you take to prevent slavery and human trafficking in your business and supply chains.

Coming soon
Policy

Supplier Code of Conduct

Sets the ethical, environmental and security standards you expect from your suppliers.

Coming soon
FAQ

Questions about the policy templates

Are the templates really free?

Yes. There is nothing to pay and no copyright restrictions, so you can edit and use the documents however you like. We ask for an email address so we can send you the finished document.

How are these templates different from a standard template?

A standard template gives everyone the same text with blanks to fill in. Ours are written from your answers about your company’s size, industry, systems, customers and regulations, so it describes how you actually work. You get an editable Word document and a PDF by email, usually within a few minutes.

Will these documents make us SOC 2 or ISO 27001 compliant?

Not on their own. Policies show auditors and customers what you have committed to, and audits then check that you follow them. The framework tags on each document show which audits commonly expect it, so you can see which ones you need.

Which policies should we write first?

Start with the Information Security Policy, then the Access Control Policy, Incident Response Plan and Disaster Recovery & Business Continuity Plan. Security questionnaires and SOC 2 and ISO 27001 auditors ask for these four more than any others.

Is this legal advice?

No. The documents are a strong first draft, not legal advice. Have someone qualified review them before you adopt them, especially customer-facing documents such as a privacy notice or data processing agreement.

When will the coming-soon documents be ready?

We are adding them in batches, starting with the documents people search for and customers ask for most: the Risk Register, Privacy Notice and DPIA Procedure come next.