Picture this: management asks the IT team to prepare every information security policy document needed for ISO 27001 certification — and the deadline is just 3 months. You open ISO 27001:2022, look at Annex A with its 93 controls, and ask: where do I even start?
For many organisations in Indonesia, the hardest part is not understanding information security concepts — it is documenting them as policies that satisfy ISO 27001. This article provides ready-made templates you can adapt for your own organisation.
Contents
- What Is an ISMS Policy?
- The 10 Mandatory ISO 27001 Documents
- Example 1: Information Security Policy
- Example 2: Acceptable Use Policy
- Example 3: Access Control Policy
- A Sample Statement of Applicability (SoA)
- Implementation Tips: From Template to Living Policy
- A 12-Month ISMS Implementation Timeline
- FAQ
What Is an ISMS Policy?
An ISMS Policy (Information Security Management System Policy) is the highest-level document setting out the organisation's commitment, direction, and principles for managing information security. It forms the foundation of the entire information security management system under ISO/IEC 27001:2022.

How the ISMS Policy Relates to ISO 27001
ISO 27001 requires an organisation to establish an information security policy under clause 5.2 — Policy. That policy must:
- Be appropriate to the organisation's purpose
- Include information security objectives, or a framework for setting them
- Include a commitment to satisfying applicable requirements
- Include a commitment to continual improvement
Beneath the main ISMS policy sits a hierarchy of supporting documents:
- Policy — A statement of intent and direction from top management ("what" and "why")
- Standard — The specific requirements that must be met ("what has to be done")
- Procedure — Detailed execution steps ("how to do it")
- Guideline — Best practice recommendations ("how it should ideally be done")
Annex A: 93 Controls in 4 Categories
ISO 27001:2022 (the latest version) simplifies Annex A into 4 categories totalling 93 controls:
| Category | Control Count | Examples |
|---|---|---|
| A.5 Organizational | 37 | Information security policies, asset management, access control |
| A.6 People | 8 | Screening, awareness, responsibilities on termination |
| A.7 Physical | 14 | Physical perimeter, clear desk, media handling |
| A.8 Technological | 34 | Endpoints, privileged access, cryptography, backup |
Note: the number of mandatory documents varies with interpretation and certification body. The list below covers what auditors most commonly ask for.
Every relevant control must be supported by a written policy, procedure, or guideline — which is why documentation is the most time-consuming part of an ISO 27001 implementation.
Want to Lead the ISO 27001 Implementation at Your Organisation?
The ISO 27001 Lead Implementer course provides the full competency to plan, implement, and maintain an ISMS to the international standard.
The 10 Mandatory ISO 27001 Documents
These are the documents that must exist to satisfy ISO 27001:2022 certification requirements:
| No | Document | ISO Clause | Description |
|---|---|---|---|
| 1 | Scope of the ISMS | 4.3 | Defines the ISMS boundary and applicability — business units, locations, assets, and technologies covered |
| 2 | Information Security Policy | 5.2 | The top-level policy stating management's commitment to information security |
| 3 | Risk Assessment Process | 6.1.2 | The risk assessment methodology: risk criteria, identification, analysis, and evaluation |
| 4 | Risk Treatment Plan | 6.1.3 | The risk treatment plan and the controls selected for mitigation |
| 5 | Statement of Applicability (SoA) | 6.1.3 d) | A list of all 93 Annex A controls with justification for applying or excluding each |
| 6 | Information Security Objectives | 6.2 | Measurable information security objectives consistent with the policy |
| 7 | Evidence of Competence | 7.2 | Evidence of competence for personnel with an ISMS role (certifications, training, experience) |
| 8 | Documented Operating Procedures | 8.1 | Operating procedures for the processes the ISMS requires |
| 9 | Results of Risk Assessment | 8.2 | Documented and maintained risk assessment results |
| 10 | Internal Audit Program & Results | 9.2 | The internal audit programme, evidence of execution, and audit findings |
Note: beyond the mandatory documents above, an organisation also needs supporting procedures such as an Access Control Policy, Acceptable Use Policy, Incident Management Procedure, Business Continuity Plan, and others depending on which Annex A controls apply.
Example 1: Information Security Policy
Here is an Information Security Policy template you can adapt. It satisfies the requirements of ISO 27001:2022 clause 5.2.
1. Purpose
This policy aims to:
- Set the direction and principles for managing information security at [Organisation Name]
- Protect the confidentiality, integrity, and availability of all information assets
- Ensure compliance with applicable legislation, including Law No. 27 of 2022 on Personal Data Protection and Government Regulation No. 71 of 2019 on Electronic Systems and Transactions
2. Scope
This policy applies to:
- All employees, contractors, and third parties accessing [Organisation Name] information assets
- All information assets in any form (digital, printed, verbal)
- All information systems, networks, and IT infrastructure managed or used by [Organisation Name]
- All operating locations: the Jakarta head office, branch offices, and remote working environments
3. Management Commitment
Top management at [Organisation Name] commits to:
- Providing adequate resources to implement and maintain the ISMS
- Setting measurable information security objectives relevant to business strategy
- Ensuring information security is integrated into all business processes
- Reviewing ISMS effectiveness periodically
- Supporting continual improvement of the ISMS
4. Information Security Principles
- Risk-based approach — Security controls are applied on the basis of risk assessment results
- Defence in depth — Layered protection at every level (physical, network, application, data)
- Least privilege — Access granted at the minimum level the role requires
- Segregation of duties — Separating duties to prevent abuse of authority
- Security by design — Security considered from the system planning stage onward
5. Roles and Responsibilities
| Role | Responsibility |
|---|---|
| Board of Directors | Setting policy, providing resources, conducting management review |
| Chief Information Security Officer (CISO) | Running the ISMS programme, reporting security performance to the board, coordinating incident response |
| Information Security Committee | Reviewing risks, approving the risk treatment plan, monitoring control execution |
| IT Department | Implementing technical controls, managing security infrastructure, monitoring logs and alerts |
| Department Heads | Identifying information assets in their own unit, ensuring staff compliance |
| All Employees | Following the policy, reporting security incidents, completing the awareness programme |
| Internal Audit | Conducting periodic audits of ISMS implementation |
6. Review Cycle
- Periodic review: At least once a year, or whenever there is a significant change
- Exceptional review triggers: A major security incident, a regulatory change, an organisational restructure, or an audit result showing a major nonconformity
- Approval: Every revision must be approved by the board
- Distribution: The latest version is communicated to all relevant parties within 5 working days of approval
Example 2: Acceptable Use Policy
An Acceptable Use Policy (AUP) governs how employees may use the organisation's IT assets. It supports control A.5.10 — Acceptable use of information and other associated assets.
Email and Internet Use
- Company email is for business purposes only. Limited personal use is permitted provided it does not affect productivity or break the law
- Sending confidential or restricted information by email without encryption is prohibited
- Accessing, downloading, or distributing illegal content, pornography, or material inciting ethnic or religious hatred is prohibited
- Using personal cloud storage (personal Google Drive, Dropbox) to store company data is prohibited — use the services IT has approved
- All internet activity may be monitored by the IT Security team for security purposes
BYOD (Bring Your Own Device) Policy
- Personal devices accessing company data must be enrolled in the MDM (Mobile Device Management) system
- The operating system and applications must be kept at the latest version
- Devices must have a screen lock (a PIN of at least 6 digits, or biometrics)
- The IT team reserves the right to remote wipe company data from a lost device or when an employee resigns
- Jailbreaking or rooting an MDM-enrolled device is prohibited
Password Policy
- A minimum length of 12 characters, combining upper case, lower case, numbers, and symbols
- Passwords must not repeat any of the last 12 used
- Password changes are mandatory every 90 days for standard accounts and 60 days for privileged accounts
- Use of an approved password manager (Bitwarden Enterprise, for example) is required
- Multi-Factor Authentication (MFA) is mandatory for all access to critical systems, VPN, and email
- Sharing a password with anyone — including a manager or the IT team — is strictly prohibited
Clean Desk and Clear Screen
- Confidential and restricted documents must not be left on a desk when leaving the work area
- Screens must be locked (Win+L or Ctrl+Cmd+Q) whenever leaving a workstation, however briefly
- Whiteboards holding sensitive information must be cleaned after a meeting
- Confidential documents no longer needed must be destroyed using a cross-cut shredder
- USB drives and portable media must be stored in a locked drawer when not in use
Breaches
Breaches of the Acceptable Use Policy are handled according to severity:
Note: NIST SP 800-63B recommends incident-based rather than periodic rotation where MFA is already in place. Periodic rotation remains common in Indonesia and is expected by many auditors, but mature organisations may consider a risk-based approach.
- Minor breach (first occurrence, unintentional) — Verbal warning and repeat training
- Moderate breach (repeated or potentially damaging) — Written warning
- Serious breach (deliberate, or resulting in a security incident) — Sanctions under company regulations, up to termination of employment
Example 3: Access Control Policy
An Access Control Policy governs how access rights to information systems and data are granted, managed, and revoked. It supports the Annex A controls A.5.15 — Access control, A.5.16 — Identity management, A.5.18 — Access rights, and A.8.2 — Privileged access rights.
The Least Privilege Principle
- Every user is granted only the minimum access required to perform their duties
- Default access for a new employee: email, intranet, and the HR system — anything further requires a formal request
- Access rights are not permanent — they are reviewed and can be revoked as roles change
- Access to the production environment is granted on a need-to-know and need-to-use basis only
Provisioning and Deprovisioning
| Process | SLA | Approval | Performed by |
|---|---|---|---|
| Onboarding (new employee) | 1 day before the start date | Department Head + IT Manager | IT Operations |
| Access change (transfer/promotion) | 3 working days | New Department Head + CISO | IT Operations |
| Temporary access (project) | 1 working day | Project Manager + IT Manager | IT Operations, auto-expiring |
| Offboarding (resignation/termination) | Same day (D+0) | HR + IT Manager | IT Operations |
| Offboarding (urgent termination) | Within 1 hour | HR Director | IT Security (on call) |
Important: on a transfer, old access must be revoked first before new access is granted. Access rights must never accumulate across departments (privilege creep).
Privileged Access Management (PAM)
- Privileged accounts (root, administrator, DBA) are separate from standard accounts — one person, two accounts
- All privileged access must go through a PAM tool with session recording
- Privileged account passwords are held in a password vault — never memorised or written down
- Privileged access is used only for administrative tasks — browsing and email use the standard account
- All privileged account activity is logged and reviewed at least weekly by the CISO
- Privileged access is re-reviewed every 3 months (quarterly access review)
Periodic Access Rights Review
- Quarterly: Review access to critical systems and privileged accounts
- Semi-annually: Review all employee access rights
- Annually: Review the access control policy and control effectiveness
- Review results are documented and reported to the Information Security Committee
Learn Best Practice for Implementing ISO 27001 Controls
On the ISO 27001 Lead Implementer course you will practise drafting policies, running a risk assessment, and building a Statement of Applicability against real case studies.
A Sample Statement of Applicability (SoA)
The Statement of Applicability (SoA) is a mandatory document (clause 6.1.3 d) listing all 93 Annex A controls along with the decision on whether each applies, complete with justification. The SoA is often called the "heart" of an ISMS, because it connects risk assessment results to the controls selected.
Here is part of an SoA for the Organizational (A.5) controls:
| Control | Description | Applicable? | Justification | Implementation Status |
|---|---|---|---|---|
| A.5.1 | Policies for information security | Yes | Mandatory — the ISMS foundation | Implemented |
| A.5.2 | Information security roles and responsibilities | Yes | Required for accountability | Implemented |
| A.5.3 | Segregation of duties | Yes | Mitigates fraud and error risk | Partially implemented |
| A.5.4 | Management responsibilities | Yes | Management commitment to the ISMS | Implemented |
| A.5.5 | Contact with authorities | Yes | Required for incident response and regulatory compliance (BSSN, the communications ministry) | Implemented |
| A.5.6 | Contact with special interest groups | Yes | For threat intelligence and knowledge sharing (ID-CERT, ISACA Indonesia) | In progress |
| A.5.7 | Threat intelligence | Yes | Required for early detection of cyber threats | Planned |
| A.5.8 | Information security in project management | Yes | Integrating security from the project design phase | Partially implemented |
| A.5.9 | Inventory of information and other associated assets | Yes | The foundation for risk assessment | Implemented |
| A.5.10 | Acceptable use of information and other associated assets | Yes | Governs user behaviour toward information assets | Implemented |
| A.5.23 | Information security for use of cloud services | Yes | The organisation uses AWS and Google Workspace | In progress |
| A.5.30 | ICT readiness for business continuity | Yes | Required to guarantee RTO and RPO | Planned |
Tip: the SoA must cover all 93 controls, not only those applied. For any control marked Not Applicable, you need strong justification — for example: "A.7.4 Physical security monitoring — Not Applicable: all operations are remote with no physical office."
Implementation Tips: From Template to Living Policy
Having a policy template is only the first step. The real challenge is making the policy genuinely operate in day-to-day work. Here is how to stop it becoming a formality gathering dust:
1. Fit It to Your Organisational Context
Do not copy templates verbatim. Every organisation has a unique context (ISO 27001 clauses 4.1 and 4.2). A fintech will emphasise different things from a manufacturer. Make sure the policy reflects:
- The industry and applicable regulation (OJK, Bank Indonesia, the communications ministry, BSSN)
- Organisation size and structure
- The technology and infrastructure in use
- Management's risk appetite
2. Use Language Everyone Understands
Policies are read by every employee, not only the IT team. Avoid excessive technical jargon. Where technical terms are unavoidable, include a glossary. Use concrete examples: "Do not use public WiFi to access work email without a VPN" lands far better than "Data transmission over untrusted networks must use transport layer encryption."
3. Get Buy-in from Top Management
A policy without top management support will not stick. Make sure:
- The board signs and communicates the policy
- Budget is allocated for control implementation
- Breaches are handled consistently, with no exception for seniority
4. Build a Continuous Awareness Programme
A single briefing at launch is not enough. Design an ongoing awareness programme:
- Security awareness training at onboarding
- Annual refresher training
- Monthly phishing simulation
- An information security newsletter
- Reminder posters and screensavers
5. Measure and Improve
Set KPIs to measure policy effectiveness:
- Security incidents per quarter
- Percentage of employees passing the security awareness test
- Average incident response time
- Phishing simulation results (click rate)
- Number of internal audit findings
A 12-Month ISMS Implementation Timeline
Here is a roadmap for implementing an ISMS from scratch to certification-ready in 12 months:
| Month | Phase | Main Activities | Output |
|---|---|---|---|
| 1-2 | Initiation & gap analysis | Gap analysis against ISO 27001:2022, defining ISMS scope, forming the implementation team, top management awareness | Gap analysis report, ISMS scope document, team appointment letter |
| 3-4 | Risk assessment | Information asset inventory, threat and vulnerability identification, risk assessment, drafting the risk treatment plan | Asset register, risk register, risk treatment plan, draft SoA |
| 5-6 | Policy drafting | Writing all mandatory policies, standards, and procedures from the risk treatment plan and SoA | Information Security Policy, AUP, Access Control Policy, final SoA, and 15+ supporting procedures |
| 7-8 | Control implementation | Implementing technical controls (firewall, SIEM, MFA, backup, encryption), physical controls (CCTV, card access), and organisational controls | Evidence of control implementation, system configuration, test reports |
| 9 | Awareness & training | Security awareness training for all employees, specialist training for IT and the incident response team | Training material, attendance lists, quiz results, awareness certificates |
| 10 | Internal audit | Internal audit by a trained auditor (or consultant), identifying nonconformities, corrective action | Internal audit report, corrective action plan, evidence of remediation |
| 11 | Management review | Presenting implementation and audit results to top management, reviewing ISMS effectiveness, deciding on improvements | Management review minutes, decisions and action items |
| 12 | Certification (Stage 1 & 2) | Stage 1: documentation review by the certification body. Stage 2: on-site audit of implementation. Handling minor findings. | ISO 27001:2022 certificate |
Note: the 12-month timeline above applies to a medium-sized organisation (100-500 employees) with dedicated resources. Larger or more complex organisations may need 15-18 months. Involving an experienced consultant can accelerate the process significantly.
Ready to Begin Your ISO 27001 Certification Journey?
The ISO 27001 Lead Implementer course at Frans Training equips you to lead an ISMS implementation from planning through to certification. Gain a deep understanding of policy drafting, risk assessment, and audit readiness through real case studies and simulations.
Synergy with the Personal Data Protection Law: Law No. 27 of 2022 on Personal Data Protection overlaps significantly with ISO 27001, particularly on data classification, access control, and incident notification. An organisation implementing ISO 27001 automatically satisfies most PDP Law requirements. Note also the obligation to appoint a Data Protection Officer under the PDP Law.
FAQ
Is ISO 27001 mandatory in Indonesia?
Generally, ISO 27001 is voluntary. Several sectors do have regulations requiring an equivalent information security standard, however — POJK No. 11/POJK.03/2022 (verify the latest regulation, as OJK actively updates its IT and cybersecurity rules) references ISO 27001 for banking, and the electronic systems and transactions regulation requires electronic system providers to apply information security risk management. In practice, many companies in financial services, healthcare, and technology treat ISO 27001 as a tender requirement or a client compliance condition.
What does ISO 27001 certification cost?
Cost varies with organisation size and ISMS scope. For a medium-sized company in Indonesia, total estimated cost covers: a consultant at IDR 150-400 million, the certification body at IDR 80-200 million, technical control implementation at IDR 100-500 million, and training at IDR 50-150 million. The total runs IDR 380 million to 1.25 billion for the first certification cycle (3 years).
What is the difference between ISO 27001:2013 and ISO 27001:2022?
The 2022 version is a significant update. The main clauses (4-10) changed only slightly, but Annex A was restructured completely: from 114 controls across 14 domains to 93 controls in 4 categories (Organizational, People, Physical, Technological). There are also 11 new controls, including threat intelligence, cloud security, and data masking. Organisations certified against the 2013 version had a transition period that ended on 31 October 2025 (this period has now closed).
April 2026 update: the transition period closed on 31 October 2025. Every certified organisation must now be on ISO 27001:2022. New certificates are issued only against the 2022 version.
Must the SoA list all 93 controls?
Yes, without exception. The Statement of Applicability must list all 93 Annex A controls. For each, you must state whether it applies, with justification. The certification auditor will check the SoA for completeness and confirm the justifications align with the risk assessment results.
How long is an ISO 27001 certificate valid?
An ISO 27001 certificate is valid for 3 years. During that period the certification body conducts an annual surveillance audit (in years 1 and 2) to confirm the ISMS is being maintained. In year 3 a recertification audit takes place, close in scope to the original certification audit.