Cloud Minds Trusted
← Blog

Information Security Policy: How to Build One in 5 Steps

By Cloud Minds Trusted

October 05, 2026 · 8 min read

An information security policy is the document in which company leadership defines how the organization protects its data, systems and people, and which rules everyone must follow. It is the foundation for more detailed standards and procedures.

For teams that run in the cloud, the policy also sets out who decides what, how access is granted and what to do when something goes wrong. This guide covers what to include and how to approve and roll out the document, in five steps.

In short

  • An information security policy is a high-level document, approved by leadership, published and acknowledged by employees.
  • It should cover access and passwords, backup, acceptable use, generative AI, incident response and cloud vendors.
  • For incidents that pose a relevant risk or harm, the controller notifies Brazil's data protection authority (ANPD) and the affected individuals within 3 business days of becoming aware.
  • Review happens at planned intervals and whenever the business, risks, technology or legislation change in a relevant way.
  • Having a policy helps, but it does not automatically make you compliant with the LGPD or ISO 27001.

What is an information security policy?

An information security policy is the high-level document in which leadership defines how the company protects its data and systems. It sets out objectives, principles, responsibilities by role and a commitment to legal requirements, and it serves as the basis for more detailed standards and procedures.

Brazil's General Data Protection Law (LGPD, Law 13,709/2018), in Article 46, requires data processing agents to adopt technical and administrative security measures. The law does not use the term "security policy", but a written policy is a practical and widely adopted way to show those measures in an organized manner.

ISO/IEC 27001:2022, in control A.5.1, describes the same idea: the policy is defined, approved by management, published, communicated to and acknowledged by personnel, and reviewed at planned intervals. A good summary of this control is available in ISMS.online's material on A.5.1.

What a high-level policy should contain

  • A definition of information security for the company.
  • A framework of objectives and principles.
  • A commitment to legal and contractual requirements.
  • A commitment to continual improvement.
  • Responsibilities by role.
  • Rules for handling exceptions.

How do you create an information security policy in 5 steps?

Start by defining scope, objectives and owners, with leadership sponsorship. Then map risks and legal requirements, write the core topics, approve and publish the document with formal acknowledgment, and finally review it at planned intervals and after incidents, measuring adherence.

Step What to do Expected outcome
1 Define scope, objectives and owners A document with an owner and leadership support
2 Map risks and legal requirements Clear priorities, including cloud data
3 Write the core topics Objective, enforceable rules
4 Approve, publish and communicate Formal acknowledgment by employees
5 Review and measure adherence A living, up-to-date policy

Step 1: scope, objectives and owners

Define what the policy covers: business units, systems, cloud environments, third parties and types of data. Write a few objectives that can be verified later.

Without leadership sponsorship, the policy becomes a forgotten file. Name who is accountable for the document and who decides on exceptions.

Step 2: risks and legal requirements

List your important assets, where personal data lives and which laws and contracts apply. Include cloud accounts and services (such as AWS, Azure or GCP), code repositories, collaboration tools and vendors.

This analysis prevents a generic policy and shows where the rules need to be stricter.

Step 3: the core topics

Write each topic in plain language, with rules that a non-technical person can follow:

  • Access and passwords: multi-factor authentication (MFA), least privilege, periodic access reviews and prompt offboarding of people who leave the company.
  • Backup: what is copied, how often, where it is stored and how restoration is tested.
  • Acceptable use: what may and may not be done with company devices, accounts and data.
  • Generative AI: approved tools, data that must never go into prompts (such as personal data and trade secrets), human review of outputs and checking with vendors on how they use data for training.
  • Incident response: who triggers the process, who decides, how to log and how to notify.
  • Vendors and cloud: selection criteria, security clauses and a notification flow in case of an incident.

On incidents, ANPD Resolution CD/ANPD No. 15/2024 (of April 24, 2024) sets out points the policy should reflect. When there is a relevant risk or harm, the controller notifies the ANPD and the affected individuals within 3 business days of becoming aware. If information is missing, a supplementary notice may follow within 20 business days after the preliminary one, and this does not extend the first deadline.

The processor must notify the controller without undue delay, so the internal and contractual notification flow needs to be written down. The company must keep a record of incidents for at least 5 years, including those that were not reported. Notification to the ANPD is made through SEI!ANPD, using a Gov.br login, as described on the official incident notification page (in Portuguese).

The notice to affected individuals must include, among other points, the nature and category of the data, the technical protection measures, the risks and impacts, the mitigation measures, the date the company became aware and the contact of the data protection officer.

Step 4: approve, publish and communicate

Leadership formally approves the document. Then publish it somewhere easy to reach, such as the intranet, and tell everyone.

Collect each employee's acknowledgment, with a recorded acceptance. Add short, recurring training with examples from the company's day-to-day work.

Step 5: review and measure adherence

ISO 27001 calls for review at planned intervals and when the business, risks, technology or legislation change. The standard does not set a number of months, so choose a frequency that fits your context.

Also review after significant incidents. Track simple indicators, such as the percentage of employees with a recorded acceptance, accounts with MFA and backup restores that were tested.

How does the policy handle shared responsibility in the cloud?

In the cloud, the provider protects the platform's infrastructure, and the company remains responsible for how it configures and uses the services, including identities, data and access. The policy should make this split clear and state who owns each control.

For AWS, the AWS Well-Architected Framework Security Pillar is an official reference guide for designing and reviewing workloads securely. It helps turn policy principles into concrete technical decisions.

The NIST Cybersecurity Framework 2.0, released in February 2024, added the Govern function to the five existing ones (Identify, Protect, Detect, Respond and Recover). This reinforces that governance, and therefore a well-defined policy, sits at the center of a security program.

If your company needs help structuring this topic, see our Security, Governance and Cloud page.

Common mistakes when writing a policy

  • Copying a ready-made template without adapting it to the company and the cloud it actually uses.
  • Writing too much. Long, technical policies do not get read. Leave the details to standards and procedures.
  • Not naming owners or a clear path for exceptions.
  • Publishing and forgetting. Without formal acknowledgment, training and review, the document loses its value.
  • Ignoring generative AI, which is already part of many teams' routine.
  • Leaving vendors out of the flow, which delays incident notifications.

Keep in mind that having a policy does not, by itself, guarantee compliance with the LGPD or ISO 27001. It is one component of a larger set of controls, processes and evidence.

According to Mayer Brown's analysis of the ANPD in 2024 (in Portuguese), recurring problems in enforcement proceedings included lack of cooperation and inadequate communication to data subjects. A clear incident flow in the policy helps avoid both.

Frequently asked questions

What is the deadline to report a security incident?

When there is a relevant risk or harm to data subjects, the controller notifies the ANPD and the affected individuals within 3 business days of becoming aware of the incident. If information is missing, the supplementary notice can be sent within 20 business days after the preliminary one.

Does every incident have to be reported to the ANPD?

No. The trigger is a relevant risk or harm to data subjects. Even so, all incidents must be recorded and kept for at least 5 years, including those that were not reported.

How often should I review the policy?

ISO 27001 calls for review at planned intervals and whenever the business, risks, technology or legislation change, without fixing a number. Choose a frequency that suits your company and record it in the document.

Does the LGPD require an information security policy?

The LGPD requires technical and administrative security measures in Article 46, but it does not use the term "information security policy". In practice, a written policy is a well-established way to organize and demonstrate those measures.

Should the policy address artificial intelligence?

It is recommended. Define approved tools, data that is banned from prompts, human review of outputs and what vendors do with the data sent to them.

Conclusion

A good information security policy is short, clear, approved by leadership and alive: acknowledged by people, reviewed regularly and tied to the reality of the cloud the company uses. Start with the scope, move through the core topics and treat review as part of the routine.

If you want help structuring or reviewing your company's policy, Cloud Minds Trusted can help. Talk to our team so we can discuss your context.

Sources

Want to assess your cloud security?

Talk to Cloud Minds Trusted.

Get in touch