A.5.1Policies for information security
Define a top-level information security policy plus supporting topic-specific policies, get them approved by management, and communicate them to staff and relevant outsiders. Review them on a schedule and after major changes.
A.5.1 is covered by 55 Sekit CSF controls. +50 more in the table below. Open in the full graph →
Mapped from the Sekit CSF
The Sekit controls that cover this requirement, lens by lens.
NIST CSF 2.0 counterparts
Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.
ISO/IEC 42001:2023 — Annex A counterparts
Cyber Essentials counterparts
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
In practice
In practice a small or mid-size company gets by with one short information security policy document that names an owner, states scope, and links out to topic-specific rules for passwords, encryption and acceptable use rather than repeating them inline. Auditors open the information security policy and check three things: a real approval date and signature from leadership, a review date that has passed and was acted on, not only printed on the cover, and evidence staff were told when it changed. The common failure is a downloaded template nobody customized, still referencing a different company or a review cycle that lapsed two years ago.
Common gaps
Questions your auditor will ask
Where regulation demands it
Related controls
Via the shared Sekit CSF topic, not the framework's own index.