Skip to main content
    NixInfinity-AI
    Documentation Guide

    Cyber Assurance Policies Checklist (Free Template Map)

    Published 11 May 2026

    Core policies you must have

    • Information security policy – the umbrella document, board-approved.
    • Acceptable use policy – signed by every member of staff at induction.
    • Access control policy – joiners/movers/leavers, MFA, least privilege.
    • Data protection / data handling policy – aligned with UK GDPR.
    • Asset management policy – how you inventory devices, software and data.
    • Patch management policy – cadence, exceptions, evidencing.
    • Backup policy – frequency, retention, restore testing.
    • Incident response plan – roles, escalation, communications.
    • Business continuity / disaster recovery plan – RTO/RPO, tested annually.
    • Supplier security policy – risk-rating and due diligence for third parties.
    • Change management policy – approval and rollback.
    • Training and awareness policy – induction and annual refresher.

    What every policy must contain

    1. Version number and date
    2. Owner (named individual, not just a role)
    3. Approver (board or senior responsible officer)
    4. Review cadence (at least annual)
    5. Scope (which entities/systems it applies to)
    6. Clear, plain-English requirements
    7. Linked procedures or evidence

    Don't make this mistake

    Auditors do not reward volume. A short, clear, signed and followed policy beats a 40-page template downloaded from the internet that no one has read. If your acceptable use policy has not been signed by the staff hired in the last 12 months, you will be marked down regardless of how good the document is.

    Mapping to the 14 themes

    See the 14 themes of Cyber Assurance for which policies map to which theme.

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions